First published: Wed May 20 2020(Updated: )
IBM Guardium Activity Insights 10.6 and 11.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 174682.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Initial Release | <=2.0.0 | |
IBM Security Guardium Insights | =2.0.0 | |
Ibm Infosphere Guardium Activity Monitor | =10.6 | |
Ibm Infosphere Guardium Activity Monitor | =11.0 | |
Linux Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4173 is a vulnerability in IBM Guardium Activity Insights 10.6 and 11.0 that does not set the secure attribute on authorization tokens or session cookies.
Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to.
The severity of CVE-2020-4173 is medium.
IBM Guardium Activity Insights 10.6 and 11.0 are affected by CVE-2020-4173.
To fix CVE-2020-4173, upgrade to a version of IBM Guardium Activity Insights that sets the secure attribute on authorization tokens and session cookies.