Session Cookie Vulnerability in IBM Rational ClearQuest Web Component
CVE-2014-3103
Currently unrated
Summary
The Web component within IBM Rational ClearQuest versions 7.1 prior to 7.1.2.15 and 8.0.x prior to 8.0.0.12 and 8.0.1.x prior to 8.0.1.5 fails to properly set the secure flag for session cookies during HTTPS sessions. This oversight allows attackers to potentially intercept and capture session cookies transmitted over unsecured HTTP, thereby facilitating unauthorized access to user sessions.
References
Timeline
Vulnerability published
Vulnerability Reserved