Cookie Transmission Flaw in IBM InfoSphere BigInsights
CVE-2014-0905
Currently unrated
What is CVE-2014-0905?
IBM InfoSphere BigInsights versions 2.0 through 2.1.2 lack proper security measures for the LTPA cookie, specifically not setting the secure flag in HTTPS sessions. This oversight allows potential attackers to intercept cookie transmissions, making sensitive user information vulnerable during unsecured HTTP connections. Implementing secure flag settings is crucial to safeguard against such risks.