First published: Thu Nov 07 2024(Updated: )
HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by an attacker using XSS, resulting in unauthorized access or session cookies could be transferred over an unencrypted channel.
Credit: psirt@hcl.com
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.