CVE-2015-1915
The Endpoint Manager for Remote Control component in IBM Tivoli Endpoint Manager for Lifecycle Management 9.0.1 before IF6 and 9.1.0 before IF6 does not set the secure flag for the session cookie in an https session, which makes it easier for remote…
Does this matter?
Lower severity and a low EPSS score (1.19%). Track it; it rarely justifies an emergency change on its own.
Description
The Endpoint Manager for Remote Control component in IBM Tivoli Endpoint Manager for Lifecycle Management 9.0.1 before IF6 and 9.1.0 before IF6 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 1.19% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/endpoint manager family
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV72069Patch, Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21882571Patch, Vendor Advisory
- http://www.securityfocus.com/bid/74193
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV72069Patch, Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21882571Patch, Vendor Advisory
- http://www.securityfocus.com/bid/74193
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.