First published: Fri Nov 05 2021(Updated: )
IBM Security SiteProtector System 3.1.1 could allow a remote attacker to obtain sensitive information, caused by missing 'HttpOnly' flag. A remote attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 174129.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM SiteProtector system | <=3.1.1 | |
IBM SiteProtector system | =3.1.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4146 has been classified with a medium severity rating.
To fix CVE-2020-4146, ensure that the 'HttpOnly' flag is set for cookies in the IBM Security SiteProtector System.
CVE-2020-4146 could allow attackers to obtain sensitive information from the affected IBM Security SiteProtector System.
CVE-2020-4146 affects IBM Security SiteProtector System version 3.1.1.0 and earlier versions.
The vendor associated with CVE-2020-4146 is IBM.