CVE-2023-29259: IBM Sterling Connect:Express for UNIX information disclosure
IBM Sterling Connect:Express for UNIX 1.5 browser UI is vulnerable to attacks that rely on the use of cookies without the SameSite attribute. IBM X-Force ID: 252055.
Other sources
IBM Sterling Connect:Express for UNIX browser UI is vulnerable to attacks that rely on the use of cookies without the SameSite attribute.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-29259.
What software is affected by this vulnerability?
IBM Sterling Connect:Express for UNIX 1.5 is affected by this vulnerability.
What is the severity level of this vulnerability?
The severity level of this vulnerability is medium with a CVSS score of 5.3.
What is the impact of this vulnerability?
This vulnerability allows attacks that rely on the use of cookies without the SameSite attribute.
Are there any references or additional information available?
Yes, you can find more information at the following links: [Vulnerability Details](https://exchange.xforce.ibmcloud.com/vulnerabilities/252055) and [IBM Support Page](https://www.ibm.com/support/pages/node/7010921).