Session Cookie Vulnerability in IBM Rational ClearQuest Web Component
CVE-2014-3103

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
23 September 2014

Summary

The Web component within IBM Rational ClearQuest versions 7.1 prior to 7.1.2.15 and 8.0.x prior to 8.0.0.12 and 8.0.1.x prior to 8.0.1.5 fails to properly set the secure flag for session cookies during HTTPS sessions. This oversight allows attackers to potentially intercept and capture session cookies transmitted over unsecured HTTP, thereby facilitating unauthorized access to user sessions.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.