First published: Wed Feb 21 2018(Updated: )
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 does not set the secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session. IBM X-Force ID: 111890.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Identity Manager Virtual Appliance | =7.0.0.0 | |
IBM Security Identity Manager Virtual Appliance | =7.0.0.1 | |
IBM Security Identity Manager Virtual Appliance | =7.0.0.2 | |
IBM Security Identity Manager Virtual Appliance | =7.0.0.3 | |
IBM Security Identity Manager Virtual Appliance | =7.0.1.0 | |
IBM Security Identity Manager Virtual Appliance | =7.0.1.1 | |
IBM Security Identity Manager Virtual Appliance | =7.0.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity level of CVE-2016-0351 is medium.
CVE-2016-0351 affects IBM Security Identity Manager Virtual Appliance versions 7.0.x before 7.0.1.3-ISS-SIM-IF0001.
CVE-2016-0351 is a vulnerability in IBM Security Identity Manager Virtual Appliance that allows remote attackers to capture the session cookie in an HTTPS session.
To fix CVE-2016-0351, update to IBM Security Identity Manager Virtual Appliance version 7.0.1.3-ISS-SIM-IF0001 or later.
For more information on CVE-2016-0351, you can refer to the following links: [IBM Security Bulletin](http://www-01.ibm.com/support/docview.wss?uid=swg21989198) and [IBM X-Force ID](https://exchange.xforce.ibmcloud.com/vulnerabilities/111890).