First published: Sun Aug 17 2014(Updated: )
IBM InfoSphere BigInsights 2.0 through 2.1.2 does not set the secure flag for the LTPA cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere BigInsights | =2.0.0.0 | |
IBM InfoSphere BigInsights | =2.1.0.0 | |
IBM InfoSphere BigInsights | =2.1.1.0 | |
IBM InfoSphere BigInsights | =2.1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-0905 is considered medium due to the potential for remote attackers to intercept sensitive cookie data.
To fix CVE-2014-0905, configure the application to set the secure flag on the LTPA cookie to ensure it is only transmitted over HTTPS connections.
CVE-2014-0905 affects IBM InfoSphere BigInsights versions 2.0.0.0, 2.1.0.0, 2.1.1.0, and 2.1.2.0.
Yes, CVE-2014-0905 can potentially lead to data breaches if attackers successfully intercept LTPA cookies.
A potential workaround for CVE-2014-0905 is to utilize additional layers of encryption for cookie transmission in your application.