CVE-2023-33860: IBM Security ReaQta information disclosure
IBM Security QRadar EDR 3.12 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.
Other sources
IBM Security ReaQta allows web pages to be stored locally which can be read by another user on the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33860?
The severity of CVE-2023-33860 is considered high due to the potential for unauthorized access via insecure session cookies.
How do I fix CVE-2023-33860?
To fix CVE-2023-33860, ensure that the secure attribute is set on all authorization tokens and session cookies in IBM Security QRadar EDR 3.12.
What are the potential exploits for CVE-2023-33860?
Potential exploits for CVE-2023-33860 include session hijacking through intercepted cookies via unsecured HTTP links.
Which versions of IBM Security QRadar EDR are affected by CVE-2023-33860?
IBM Security QRadar EDR version 3.12 is affected by CVE-2023-33860.
Can CVE-2023-33860 lead to data breaches?
Yes, CVE-2023-33860 can lead to data breaches if attackers exploit the insecure cookie handling to gain unauthorized access.