First published: Wed Feb 05 2020(Updated: )
IBM Workflow for Bluemix does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Workflow |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0102 is classified as a moderate severity vulnerability due to its potential for session hijacking.
To fix CVE-2015-0102, ensure that the secure flag is set on session cookies during HTTPS sessions.
CVE-2015-0102 affects IBM Workflow for Bluemix, specifically its handling of session cookies.
Yes, CVE-2015-0102 can enable remote attackers to capture session cookies and potentially compromise user sessions.
CVE-2015-0102 is a known vulnerability that highlights the importance of secure cookie management in web applications.