IBM Control Desk 7.6.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 219126.
2022-09-13T21:15:09.040
2024-11-21T06:46:39.287
Modified
CVSSv3.1: 5.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | control_desk | 7.6.0 | Yes |
Application | ibm | control_desk | 7.6.0.1 | Yes |
Application | ibm | control_desk | 7.6.1 | Yes |
Application | ibm | control_desk | 7.6.1.1 | Yes |
Application | ibm | control_desk | 7.6.1.2 | Yes |
Application | ibm | control_desk | 7.6.1.3 | Yes |
Operating System | linux | linux_kernel | - | No |