CVE-2015-0102: High severity ibm workflow vulnerability
IBM Workflow for Bluemix does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0102?
CVE-2015-0102 is classified as a moderate severity vulnerability due to its potential for session hijacking.
How do I fix CVE-2015-0102?
To fix CVE-2015-0102, ensure that the secure flag is set on session cookies during HTTPS sessions.
What does CVE-2015-0102 affect?
CVE-2015-0102 affects IBM Workflow for Bluemix, specifically its handling of session cookies.
Can CVE-2015-0102 lead to information theft?
Yes, CVE-2015-0102 can enable remote attackers to capture session cookies and potentially compromise user sessions.
Is CVE-2015-0102 a common vulnerability?
CVE-2015-0102 is a known vulnerability that highlights the importance of secure cookie management in web applications.