VulnerabilityModified
CVE-2019-8283
This allows malicious javascript to steal it.
MEDIUM 6.5EPSS 1.19%
Does this matter?
Lower severity and a low EPSS score (1.19%). Track it; it rarely justifies an emergency change on its own.
Description
Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag. This allows malicious javascript to steal it.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 1.19% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1004, CWE-732
- Affected
- gemalto/sentinel ldk
- Source
- vulnerability@kaspersky.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.