CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C
AI Score
Confidence
High
EPSS
Percentile
27.9%
OOTB build scripts does not set the secure attribute on session cookie which may impact IBM Curam Social Program Management 7.0.9 and 7.0,10. The purpose of the βsecureβ attribute is to prevent cookies from being observed by unauthorized parties. IBM X-Force ID: 189158.
[
{
"product": "Curam SPM",
"vendor": "IBM",
"versions": [
{
"status": "affected",
"version": "7.0.9"
},
{
"status": "affected",
"version": "7.0.10"
}
]
}
]
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C
AI Score
Confidence
High
EPSS
Percentile
27.9%