First published: Thu Jun 08 2017(Updated: )
IBM Tivoli Federated Identity Manager 6.2 is affected by a vulnerability due to a missing secure attribute in encrypted session (SSL) cookie. IBM X-Force ID: 125731.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Federated Identity Manager | =6.2.0 | |
IBM Tivoli Federated Identity Manager | =6.2.1 | |
IBM Tivoli Federated Identity Manager | =6.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1319 is classified as a medium-severity vulnerability due to the lack of secure attributes in SSL cookies.
To fix CVE-2017-1319, ensure that secure attributes are added to encrypted session cookies in IBM Tivoli Federated Identity Manager.
CVE-2017-1319 affects version 6.2.0, 6.2.1, and 6.2.2 of IBM Tivoli Federated Identity Manager.
CVE-2017-1319 may allow an attacker to exploit insecure cookies, potentially leading to session hijacking.
Currently, the recommended approach for CVE-2017-1319 is to apply the necessary updates that include secure cookie configurations.