First published: Fri Jun 07 2019(Updated: )
Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag. This allows malicious javascript to steal it.
Credit: vulnerability@kaspersky.com
Affected Software | Affected Version | How to fix |
---|---|---|
Thales Sentinel LDK | <7.92 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-8283 is rated as high due to the potential for cookie theft by malicious scripts.
To fix CVE-2019-8283, update to version 7.92 or later of the Gemalto Sentinel LDK.
The impact of CVE-2019-8283 includes unauthorized access to user sessions as a result of stolen cookies.
CVE-2019-8283 affects all versions of the Gemalto Sentinel LDK prior to 7.92.
CVE-2019-8283 is a cross-site scripting vulnerability related to the lack of the 'HttpOnly' flag on the Hasplm cookie.