CVE-2014-0634: Input Validation
EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0634?
CVE-2014-0634 is considered a medium severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2014-0634?
To fix CVE-2014-0634, upgrade to EMC VPLEX GeoSynchrony version 5.3 or later.
What systems are affected by CVE-2014-0634?
CVE-2014-0634 affects EMC VPLEX GeoSynchrony versions 4.0, 5.0, 5.1, 5.2, and 5.2.1.
What is the nature of the vulnerability in CVE-2014-0634?
CVE-2014-0634 is a security flaw that allows attackers to access cookies without the HTTPOnly flag, increasing the risk of information theft.
Is CVE-2014-0634 related to cross-site scripting (XSS)?
CVE-2014-0634 is related to cookie security and may facilitate cross-site scripting (XSS) attacks by exposing cookie data.