HTTPOnly Flag Absence in IBM Tivoli Endpoint Manager Web Programs
CVE-2012-1837
Currently unrated
What is CVE-2012-1837?
The webreports, post/create-role, and post/update-role programs within IBM Tivoli Endpoint Manager prior to version 8.2 do not implement the HTTPOnly flag in their Set-Cookie headers. This oversight allows remote attackers to access sensitive information contained within cookies, increasing the risk of exploitation through script access. Without proper protection, these cookies can be compromised, leading to unauthorized access and data breaches.