CVE-2020-4780: Medium severity ibm curam social program management vulnerability
OOTB build scripts does not set the secure attribute on session cookie which may impact IBM Curam Social Program Management 7.0.9 and 7.0,10. The purpose of the 'secure' attribute is to prevent cookies from being observed by unauthorized parties. IBM X-Force ID: 189158.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-4780.
What is the severity level of CVE-2020-4780?
The severity level of CVE-2020-4780 is medium with a CVSS score of 5.3.
How does the lack of 'secure' attribute on session cookie impact IBM Curam Social Program Management?
The lack of 'secure' attribute on session cookie may allow unauthorized parties to observe the cookies of IBM Curam Social Program Management users.
Which versions of IBM Curam Social Program Management are affected by this vulnerability?
This vulnerability affects version 7.0.9.0 and 7.0.10.0 of IBM Curam Social Program Management.
How can I fix the lack of 'secure' attribute on session cookie for IBM Curam Social Program Management?
To fix this vulnerability, ensure that the secure attribute is set on the session cookie in IBM Curam Social Program Management build scripts.