Overview
- Description
- IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 158876.
- Source
- psirt@us.ibm.com
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 3.7
- Impact score
- 1.4
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity
- LOW
CVSS 3.0
- Type
- Secondary
- Base score
- 3.7
- Impact score
- 1.4
- Exploitability score
- 2.2
- Vector string
- CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity
- LOW
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-311
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:cognos_controller:10.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7B9021EE-6BDF-4722-A7EA-E984A21684A7" }, { "criteria": "cpe:2.3:a:ibm:cognos_controller:10.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F544128B-455B-4485-A98F-4DB751925B36" }, { "criteria": "cpe:2.3:a:ibm:cognos_controller:10.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8284ECE5-3938-47B2-99B6-6D3B9ECB8C82" }, { "criteria": "cpe:2.3:a:ibm:cognos_controller:10.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "04E5A9C3-0F44-40C1-B6B6-92839E386F56" } ], "operator": "OR" } ] } ]