CVE-2019-4563: Medium severity IBM Security Directory Server vulnerability
IBM Security Directory Server 6.4.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 166624.
Other sources
IBM Security Directory Server does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this IBM Security Directory Server vulnerability?
The vulnerability ID for this IBM Security Directory Server vulnerability is CVE-2019-4563.
What is the severity score of CVE-2019-4563?
The severity score of CVE-2019-4563 is 5.3 (medium).
What is the impact of the vulnerability described in CVE-2019-4563?
The vulnerability described in CVE-2019-4563 allows attackers to potentially obtain cookie values by sending a malicious link or planting it on a website the user visits.
Which products and versions are affected by CVE-2019-4563?
IBM Security Directory Server version 6.4.0 is specifically affected by CVE-2019-4563.
Are there any references available for more information about CVE-2019-4563?
Yes, you can find more information about CVE-2019-4563 at the following references: [1] https://exchange.xforce.ibmcloud.com/vulnerabilities/166624 [2] https://www.ibm.com/support/pages/node/6356607