CVE-2016-0353: Infoleak
IBM Security Privileged Identity Manager 2.0 before 2.0.2 FP8, when Virtual Appliance is used, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0353?
CVE-2016-0353 is rated as a high severity vulnerability due to its potential for remote cookie interception.
How do I fix CVE-2016-0353?
To resolve CVE-2016-0353, upgrade IBM Security Privileged Identity Manager to version 2.0.2 FP8 or newer.
What type of vulnerability is CVE-2016-0353?
CVE-2016-0353 is a security vulnerability related to improper session cookie management in HTTPS situations.
Who is affected by CVE-2016-0353?
Organizations using IBM Security Privileged Identity Manager versions 2.0.0 through 2.0.2 are affected by CVE-2016-0353.
What can attackers do with CVE-2016-0353?
Attackers can capture session cookies, potentially allowing them to hijack user sessions.