First published: Thu Mar 22 2012(Updated: )
The (1) webreports, (2) post/create-role, and (3) post/update-role programs in IBM Tivoli Endpoint Manager (TEM) before 8.2 do not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Endpoint Manager | <=8.1 | |
IBM Endpoint Manager | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1837 has been rated as a medium severity vulnerability.
To mitigate CVE-2012-1837, upgrade IBM Tivoli Endpoint Manager to version 8.2 or later.
CVE-2012-1837 can allow remote attackers to obtain sensitive information via script access due to the lack of the HTTPOnly flag in cookies.
CVE-2012-1837 affects IBM Tivoli Endpoint Manager versions before 8.2, including version 8.0 and 8.1.
The webreports, post/create-role, and post/update-role programs in IBM Tivoli Endpoint Manager are affected by CVE-2012-1837.