First published: Fri Oct 16 2020(Updated: )
IBM Spectrum Scale 5.0.0 through 5.0.5.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 188518.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Scale | >5.0.0.0<=5.0.5.2 | |
<=5.0.0 - 5.0.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-4749.
The severity level of CVE-2020-4749 is medium.
IBM Spectrum Scale versions 5.0.0 through 5.0.5.2 are affected by CVE-2020-4749.
Attackers can exploit CVE-2020-4749 by sending a http:// link to a user or by planting this link in a site the user goes to.
Yes, you can find references for CVE-2020-4749 at the following links: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/188518), [Reference 2](https://www.ibm.com/support/pages/node/6349449).