Information Disclosure Vulnerability in IBM Security SiteProtector
CVE-2020-4146
4MEDIUM
Summary
IBM Security SiteProtector System 3.1.1 is vulnerable due to the absence of the 'HttpOnly' flag in its security settings. This lack of protection allows remote attackers to exploit the vulnerability and potentially access sensitive information stored in cookies, exposing users to data theft and unauthorized access. It is crucial for organizations using this product to implement necessary security measures to mitigate the risk associated with this vulnerability.
Affected Version(s)
Security SiteProtector System 3.1.1
References
CVSS V3.1
Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved