CVE-2018-1948
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 153428.
IBM Security Identity Governance and Intelligence, desde la versión 5.2 hasta la 5.2.4.1 Virtual Appliance, no establece el atributo seguro en tokens de autorización o en cookies de sesión. Los atacantes podrían obtener los valores de dichas cookies, enviando un enlace http:// a un usuario o embebiendo el mismo en un sitio web visitado por el usuario. Se enviará la cookie al enlace inseguro y el atacante podrá obtener el valor de la misma escuchando el tráfico. IBM X-Force ID: 153428.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-12-13 CVE Reserved
- 2019-02-21 CVE Published
- 2024-07-11 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-384: Session Fixation
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.ibm.com/support/docview.wss?uid=ibm10872142 | 2019-10-09 |
URL | Date | SRC |
---|---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/153428 | 2019-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Security Identity Governance And Intelligence Search vendor "Ibm" for product "Security Identity Governance And Intelligence" | >= 5.2 <= 5.2.4.1 Search vendor "Ibm" for product "Security Identity Governance And Intelligence" and version " >= 5.2 <= 5.2.4.1" | - |
Affected
|