First published: Fri Jul 31 2015(Updated: )
Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/Red Hat AMQ | <6.3. | 6.3. |
Red Hat AMQ | <6.3 | |
Red Hat JBoss A-MQ | =7 | |
Red Hat JBoss Enterprise Web Server | =1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2015-5183 is classified as a High severity vulnerability due to its impact on sensitive cookie attributes.
To fix CVE-2015-5183, update Red Hat AMQ to version 6.3 or later to ensure HTTPOnly and Secure attributes are properly set on cookies.
Exploitation of CVE-2015-5183 can allow attackers to access authenticated session IDs and potentially conduct further malicious actions.
CVE-2015-5183 affects Red Hat AMQ versions prior to 6.3.
If using JBoss A-MQ version 7, you should verify if you are also using components that may be impacted by CVE-2015-5183, even though version 7 itself is not directly affected.