First published: Tue Aug 16 2022(Updated: )
IBM Control Desk 7.6.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 219126.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Control Desk | =7.6.0 | |
IBM Control Desk | =7.6.0.1 | |
IBM Control Desk | =7.6.1 | |
IBM Control Desk | =7.6.1.1 | |
IBM Control Desk | =7.6.1.2 | |
IBM Control Desk | =7.6.1.3 | |
Linux Linux kernel | ||
IBM Control Desk | <=IBM Control Desk 7.6.x |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-22330.
The title of this vulnerability is 'IBM Control Desk could allow a remote attacker to obtain sensitive information caused by the failure...'
The severity rating of this vulnerability is medium with a score of 5.3.
The affected software for this vulnerability is IBM Control Desk versions 7.6.0, 7.6.0.1, 7.6.1, 7.6.1.1, 7.6.1.2, and 7.6.1.3.
A remote attacker can exploit this vulnerability to obtain sensitive information from the cookie.