CVE-2022-38386: IBM Cloud Pak for Security information disclosure
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10.12.0 through 1.10.19.0 does not set the SameSite attribute for sensitive cookies which could allow an attacker to obtain sensitive information using man-in-the-middle techniques. IBM X-Force ID: 233778.
Other sources
IBM Cloud Pak for Security (CP4S) does not set the SameSite attribute for sensitive cookies which could allow an attacker to obtain sensitive information using man-in-the-middle techniques.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-38386?
CVE-2022-38386 is classified as a moderate severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2022-38386?
To fix CVE-2022-38386, ensure that the SameSite attribute is set for sensitive cookies in IBM Cloud Pak for Security and IBM QRadar Suite Software.
What versions are affected by CVE-2022-38386?
CVE-2022-38386 affects IBM Cloud Pak for Security versions 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software versions 1.10.12.0 through 1.10.19.0.
What type of attacks can exploit CVE-2022-38386?
CVE-2022-38386 can be exploited through man-in-the-middle attacks that target unprotected sensitive cookies.
Is CVE-2022-38386 a web application vulnerability?
Yes, CVE-2022-38386 is considered a web application vulnerability due to the improper handling of cookie attributes in web applications.