CVE-2012-5936: Medium severity ibm b2b sterling integrator vulnerability
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5936?
CVE-2012-5936 has a medium severity due to its potential to allow remote attackers to intercept session cookies.
How do I fix CVE-2012-5936?
To fix CVE-2012-5936, ensure that the secure flag is set for the session cookie in the HTTPS configuration.
Which versions are affected by CVE-2012-5936?
CVE-2012-5936 affects IBM Sterling B2B Integrator versions 5.1 and 5.2, along with Sterling File Gateway versions 2.1 and 2.2.
What are the potential impacts of CVE-2012-5936?
The potential impacts of CVE-2012-5936 include session hijacking due to the interception of unprotected session cookies.
Is CVE-2012-5936 a client-side or server-side vulnerability?
CVE-2012-5936 is primarily a server-side vulnerability that affects how session cookies are managed.