VulnerabilityModified
CVE-2018-1480
If a Cross-Site Scripting vulnerability also existed attackers may be able to get the cookie values via malicious JavaScript and then hijack the user session.
MEDIUM 5.3EPSS 1.13%
Does this matter?
Lower severity and a low EPSS score (1.13%). Track it; it rarely justifies an emergency change on its own.
Description
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the 'HttpOnly' attribute on authorization tokens or session cookies. If a Cross-Site Scripting vulnerability also existed attackers may be able to get the cookie values via malicious JavaScript and then hijack the user session. IBM X-Force ID: 140762.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.13% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-384
- Affected
- ibm/bigfix platform
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/140762VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10733605Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/140762VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10733605Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.