CVE-2015-1994: Infoleak
IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1994?
CVE-2015-1994 has been rated as a moderate severity vulnerability.
How do I fix CVE-2015-1994?
To fix CVE-2015-1994, upgrade IBM Security QRadar Incident Forensics to version 7.2.5 Patch 5 or later.
What types of systems are affected by CVE-2015-1994?
CVE-2015-1994 affects IBM Security QRadar Incident Forensics versions 7.2.0 through 7.2.4.
What is the impact of CVE-2015-1994?
The impact of CVE-2015-1994 is that it allows remote attackers to capture session cookies containing sensitive information.
What does the HTTPOnly flag do in relation to CVE-2015-1994?
The HTTPOnly flag helps prevent client-side scripts from accessing session cookies, thus protecting sensitive data against certain types of attacks.