First published: Mon Oct 28 2019(Updated: )
IBM Security Guardium Big Data Intelligence (SonarG) does not set the secure attribute for cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Guardium Big Data Intelligence | =4.0 | |
<=4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4330 has a moderate severity level due to the potential for exposing sensitive cookie data over non-secure HTTP connections.
To fix CVE-2019-4330, update IBM Security Guardium Big Data Intelligence to version 4.1 or later, which sets the secure attribute for cookies.
CVE-2019-4330 affects IBM Security Guardium Big Data Intelligence version 4.0 and earlier.
If CVE-2019-4330 is exploited, cookies may be sent in plaintext over HTTP, potentially leading to session hijacking or data leakage.
There are no official workarounds for CVE-2019-4330; the recommended action is to upgrade to a secure version.