Session Cookie Vulnerability in BigFix Inventory by HCL Technologies
CVE-2020-14248
5.3MEDIUM
Summary
BigFix Inventory versions up to 10.0.2 are vulnerable due to the failure to set the secure flag on session cookies during HTTPS sessions. This oversight permits cookies to be transmitted over unencrypted HTTP requests, exposing them to potential interception by remote attackers. Consequently, attackers could capture sensitive session data, compromising user accounts and potentially gaining unauthorized access to protected resources.
Affected Version(s)
HCL BigFix Inventory v9, v10.0.x
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved