First published: Fri Mar 28 2014(Updated: )
EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC VPLEX GeoSynchrony | =4.0 | |
Dell EMC VPLEX GeoSynchrony | =5.0 | |
Dell EMC VPLEX GeoSynchrony | =5.1 | |
Dell EMC VPLEX GeoSynchrony | =5.2 | |
Dell EMC VPLEX GeoSynchrony | =5.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0634 is considered a medium severity vulnerability due to the potential exposure of sensitive information.
To fix CVE-2014-0634, upgrade to EMC VPLEX GeoSynchrony version 5.3 or later.
CVE-2014-0634 affects EMC VPLEX GeoSynchrony versions 4.0, 5.0, 5.1, 5.2, and 5.2.1.
CVE-2014-0634 is a security flaw that allows attackers to access cookies without the HTTPOnly flag, increasing the risk of information theft.
CVE-2014-0634 is related to cookie security and may facilitate cross-site scripting (XSS) attacks by exposing cookie data.