First published: Tue Jun 14 2022(Updated: )
In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Softwareag Connx | =6.2.0.1269 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40649 is a vulnerability in Connx Version 6.2.0.1269 (20210623) where a cookie can be issued by the application without the HttpOnly flag set.
CVE-2021-40649 has a severity rating of 6.5 (Medium).
Connx Version 6.2.0.1269 (20210623) is affected by CVE-2021-40649.
To fix CVE-2021-40649, update Connx to a version where the HttpOnly flag is properly set for cookies.
You can find more information about CVE-2021-40649 on the Connx website and the GitHub repository for CVE-2021-40649.