- Description
- EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
- Source
- security_alert@emc.com
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 6
- Impact score
- 6.4
- Exploitability score
- 6.8
- Vector string
- AV:N/AC:M/Au:S/C:P/I:P/A:P
- nvd@nist.gov
- CWE-20
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:emc:vplex_geosynchrony:4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C283DEAD-A5DB-4A74-84F6-749BFC265F2E"
},
{
"criteria": "cpe:2.3:a:emc:vplex_geosynchrony:5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D536831F-D76F-42CE-9351-3212027C8227"
},
{
"criteria": "cpe:2.3:a:emc:vplex_geosynchrony:5.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8BDBBB7B-19C8-404F-B22F-D3077EEF33F4"
},
{
"criteria": "cpe:2.3:a:emc:vplex_geosynchrony:5.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2E6877D1-61BC-4A30-91AF-0948977B0C8D"
},
{
"criteria": "cpe:2.3:a:emc:vplex_geosynchrony:5.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E2A7C8A7-5F49-4B09-B6C1-9F2F2F0A314A"
}
],
"operator": "OR"
}
]
}
]