First published: Mon Dec 21 2020(Updated: )
IBM Security Identity Governance and Intelligence 5.2.6 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 192423.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Identity Governance and Intelligence | =5.2.6 | |
<=5.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-4966 is medium with a severity value of 4.3.
CVE-2020-4966 is a vulnerability in IBM Security Identity Governance and Intelligence 5.2.6 that allows attackers to obtain cookie values by sending a malicious link to a user or planting the link on a visited website.
CVE-2020-4966 affects IBM Security Identity Governance and Intelligence 5.2.6 by not setting the secure attribute on authorization tokens or session cookies.
An attacker can exploit CVE-2020-4966 by sending a http:// link to a user or planting the link in a visited website to obtain the cookie values.
Yes, you can find references for CVE-2020-4966 at the following links: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/192423) [Reference 2](https://www.ibm.com/support/pages/node/6403233).