VulnerabilityModified
CVE-2020-4780
The purpose of the 'secure' attribute is to prevent cookies from being observed by unauthorized parties.
MEDIUM 5.3EPSS 1.00%
Does this matter?
Lower severity and a low EPSS score (1.00%). Track it; it rarely justifies an emergency change on its own.
Description
OOTB build scripts does not set the secure attribute on session cookie which may impact IBM Curam Social Program Management 7.0.9 and 7.0,10. The purpose of the 'secure' attribute is to prevent cookies from being observed by unauthorized parties. IBM X-Force ID: 189158.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.00% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-613
- Affected
- ibm/curam social program management
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/189158VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6346581Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/189158VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6346581Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.