Information Disclosure Vulnerability in IBM Security SiteProtector
CVE-2020-4146

4MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
12 November 2021

Summary

IBM Security SiteProtector System 3.1.1 is vulnerable due to the absence of the 'HttpOnly' flag in its security settings. This lack of protection allows remote attackers to exploit the vulnerability and potentially access sensitive information stored in cookies, exposing users to data theft and unauthorized access. It is crucial for organizations using this product to implement necessary security measures to mitigate the risk associated with this vulnerability.

Affected Version(s)

Security SiteProtector System 3.1.1

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.