First published: Tue Aug 16 2022(Updated: )
IBM Control Desk 7.6.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 219124.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Control Desk | <=IBM Control Desk 7.6.x | |
IBM Control Desk | =7.6.0 | |
IBM Control Desk | =7.6.0.1 | |
IBM Control Desk | =7.6.1 | |
IBM Control Desk | =7.6.1.1 | |
IBM Control Desk | =7.6.1.2 | |
IBM Control Desk | =7.6.1.3 | |
Linux Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-22329.
The severity level of CVE-2022-22329 is medium.
IBM Control Desk 7.6.1 does not set the secure attribute on authorization tokens or session cookies.
Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to.
No, Linux Linux kernel is not affected by CVE-2022-22329.
You can find more information about CVE-2022-22329 at the following references: [1](https://exchange.xforce.ibmcloud.com/vulnerabilities/219124) [2](https://www.ibm.com/support/pages/node/6619739)