Session Cookie Vulnerability in BigFix Inventory by HCL Technologies
CVE-2020-14248
5.3MEDIUM
What is CVE-2020-14248?
BigFix Inventory versions up to 10.0.2 are vulnerable due to the failure to set the secure flag on session cookies during HTTPS sessions. This oversight permits cookies to be transmitted over unencrypted HTTP requests, exposing them to potential interception by remote attackers. Consequently, attackers could capture sensitive session data, compromising user accounts and potentially gaining unauthorized access to protected resources.
Affected Version(s)
HCL BigFix Inventory v9, v10.0.x