Cookie Transmission Flaw in IBM InfoSphere BigInsights
CVE-2014-0905
Currently unrated
Summary
IBM InfoSphere BigInsights versions 2.0 through 2.1.2 lack proper security measures for the LTPA cookie, specifically not setting the secure flag in HTTPS sessions. This oversight allows potential attackers to intercept cookie transmissions, making sensitive user information vulnerable during unsecured HTTP connections. Implementing secure flag settings is crucial to safeguard against such risks.
References
Timeline
Vulnerability published
Vulnerability Reserved