Session Cookie Vulnerability in IBM Publishing Engine
CVE-2020-4316
What is CVE-2020-4316?
IBM Publishing Engine versions 6.0.6, 6.0.6.1, and 7.0 exhibit a security flaw where the secure attribute is not set on authorization tokens or session cookies. This oversight allows attackers to potentially harvest cookie values by tricking users into clicking on a malicious link or embedding the link within a compromised site. Consequently, the cookies could be transmitted over insecure connections, making them vulnerable to interception during transmission, which could lead to unauthorized access or data exfiltration.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Rational Publishing Engine 6.0.6
Rational Publishing Engine 6.0.6.1
Rational Publishing Engine 7.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved