First published: Thu Nov 24 2016(Updated: )
IBM Security Privileged Identity Manager 2.0 before 2.0.2 FP8, when Virtual Appliance is used, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Privileged Identity Manager | =2.0.0 | |
IBM Security Privileged Identity Manager | =2.0.1 | |
IBM Security Privileged Identity Manager | =2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0353 is rated as a high severity vulnerability due to its potential for remote cookie interception.
To resolve CVE-2016-0353, upgrade IBM Security Privileged Identity Manager to version 2.0.2 FP8 or newer.
CVE-2016-0353 is a security vulnerability related to improper session cookie management in HTTPS situations.
Organizations using IBM Security Privileged Identity Manager versions 2.0.0 through 2.0.2 are affected by CVE-2016-0353.
Attackers can capture session cookies, potentially allowing them to hijack user sessions.