Session Cookie Vulnerability in BigFix Inventory by HCL Technologies
CVE-2020-14248

5.3MEDIUM

Key Information:

Vendor
CVE Published:
16 December 2020

Summary

BigFix Inventory versions up to 10.0.2 are vulnerable due to the failure to set the secure flag on session cookies during HTTPS sessions. This oversight permits cookies to be transmitted over unencrypted HTTP requests, exposing them to potential interception by remote attackers. Consequently, attackers could capture sensitive session data, compromising user accounts and potentially gaining unauthorized access to protected resources.

Affected Version(s)

HCL BigFix Inventory v9, v10.0.x

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.