VulnerabilityModified
CVE-2012-5936
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission…
MEDIUM 5.0EPSS 1.36%
Does this matter?
Lower severity and a low EPSS score (1.36%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.36% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- ibm/sterling b2b integrator · ibm/sterling file gateway
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21627985Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21640830Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80401
- http://www-01.ibm.com/support/docview.wss?uid=swg21627985Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21640830Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80401
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.