Session Cookie Vulnerability in IBM Rational ClearQuest Web Component
CVE-2014-3103
Currently unrated
What is CVE-2014-3103?
The Web component within IBM Rational ClearQuest versions 7.1 prior to 7.1.2.15 and 8.0.x prior to 8.0.0.12 and 8.0.1.x prior to 8.0.1.5 fails to properly set the secure flag for session cookies during HTTPS sessions. This oversight allows attackers to potentially intercept and capture session cookies transmitted over unsecured HTTP, thereby facilitating unauthorized access to user sessions.