Cookie Transmission Flaw in IBM InfoSphere BigInsights
CVE-2014-0905

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
17 August 2014

Summary

IBM InfoSphere BigInsights versions 2.0 through 2.1.2 lack proper security measures for the LTPA cookie, specifically not setting the secure flag in HTTPS sessions. This oversight allows potential attackers to intercept cookie transmissions, making sensitive user information vulnerable during unsecured HTTP connections. Implementing secure flag settings is crucial to safeguard against such risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.