Description
IBM Security QRadar EDR 3.12 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.
References
https://www.ibm.com/support/pages/node/7159770
Vendor Advisory
https://www.ibm.com/support/pages/node/7159770
Vendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
5.3 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2024-07-10T14:15:03.060Z
1 year agoLast modified
2025-05-19T14:15:24.833Z
7 months ago