First published: Thu Apr 07 2022(Updated: )
Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI)
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Bigfix Webui |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27764 is a vulnerability where one or more cookies were set without the Secure or HTTPOnly flags.
CVE-2021-27764 has a severity level of high, with a severity value of 6.5.
CVE-2021-27764 affects Hcltech Bigfix Webui by allowing cookies to be set without the Secure or HTTPOnly flags.
To fix CVE-2021-27764, ensure that cookies are set with the Secure and HTTPOnly flags in Hcltech Bigfix Webui.
More information about CVE-2021-27764 can be found at the following reference: https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0097778