Lucene search

K
cve[email protected]CVE-2012-1837
HistoryMar 22, 2012 - 3:28 a.m.

CVE-2012-1837

2012-03-2203:28:04
CWE-200
web.nvd.nist.gov
22
cve-2012-1837
ibm tivoli endpoint manager
tem
vulnerability
information security
httponly
set-cookie
remote attackers

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.1

Confidence

Low

EPSS

0.003

Percentile

69.9%

The (1) webreports, (2) post/create-role, and (3) post/update-role programs in IBM Tivoli Endpoint Manager (TEM) before 8.2 do not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

Affected configurations

NVD
Node
ibmtivoli_endpoint_managerRange8.1
OR
ibmtivoli_endpoint_managerMatch8.0
VendorProductVersionCPE
ibmtivoli_endpoint_manager8.0cpe:/a:ibm:tivoli_endpoint_manager:8.0:::
ibmtivoli_endpoint_managercpe:/a:ibm:tivoli_endpoint_manager::::

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.1

Confidence

Low

EPSS

0.003

Percentile

69.9%

Related for CVE-2012-1837