Lucene search

K
cvelistRedhatCVELIST:CVE-2016-5409
HistoryApr 20, 2017 - 5:00 p.m.

CVE-2016-5409

2017-04-2017:00:00
redhat
www.cve.org
4

AI Score

7.4

Confidence

High

EPSS

0.003

Percentile

69.0%

Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to the cookies.

AI Score

7.4

Confidence

High

EPSS

0.003

Percentile

69.0%

Related for CVELIST:CVE-2016-5409