First published: Mon Jul 13 2020(Updated: )
IBM Publishing Engine 6.0.6, 6.0.6.1, and 7.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 177354.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Publishing Engine | =7.0 | |
IBM Rational Publishing Engine | =6.0.6 | |
IBM Rational Publishing Engine | =6.0.6.1 | |
<=6.0.6.1 | ||
<=6.0.6 | ||
<=7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4316 is a vulnerability in IBM Publishing Engine that allows attackers to obtain cookie values by sending a link or planting a link in a site the user visits.
CVE-2020-4316 affects IBM Publishing Engine versions 6.0.6, 6.0.6.1, and 7.0.
CVE-2020-4316 has a severity rating of 4.7, which is considered medium.
Attackers can exploit CVE-2020-4316 by sending a http:// link to a user or by planting this link in a site the user goes to.
Yes, you can find more information about CVE-2020-4316 at the following references: [IBM X-Force Exchange](https://exchange.xforce.ibmcloud.com/vulnerabilities/177354) and [IBM Support](https://www.ibm.com/support/pages/node/6249131).