First published: Mon Oct 12 2020(Updated: )
OOTB build scripts does not set the secure attribute on session cookie which may impact IBM Curam Social Program Management 7.0.9 and 7.0,10. The purpose of the 'secure' attribute is to prevent cookies from being observed by unauthorized parties. IBM X-Force ID: 189158.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Curam Social Program Management | =7.0.9.0 | |
IBM Curam Social Program Management | =7.0.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-4780.
The severity level of CVE-2020-4780 is medium with a CVSS score of 5.3.
The lack of 'secure' attribute on session cookie may allow unauthorized parties to observe the cookies of IBM Curam Social Program Management users.
This vulnerability affects version 7.0.9.0 and 7.0.10.0 of IBM Curam Social Program Management.
To fix this vulnerability, ensure that the secure attribute is set on the session cookie in IBM Curam Social Program Management build scripts.