Session Cookie Vulnerability in IBM Control Desk by IBM
CVE-2022-22329
4.3MEDIUM
What is CVE-2022-22329?
IBM Control Desk 7.6.1 suffers from a vulnerability where the secure attribute is not properly set on authorization tokens or session cookies. This oversight allows attackers to exploit insecure connections, potentially retrieving cookie values by embedding malicious links that users might encounter. When users unwittingly click on these links, the cookies are transmitted over an insecure HTTP connection, exposing sensitive information that can be harvested by attackers monitoring the traffic.
Affected Version(s)
Control Desk 7.6.1