Cookie Management Flaw in IBM Concert Products
CVE-2024-43177
9.8CRITICAL
Summary
IBM Concert versions 1.0.0 and 1.0.1 are impacted by a vulnerability that stems from improper handling of cookies lacking the SameSite attribute. This oversight may expose users to various security threats, such as cross-site request forgery (CSRF) attacks, where malicious third parties could exploit the lack of cookie restrictions to execute unauthorized actions. Organizations using these versions are advised to implement necessary mitigations and consider updates from IBM to enhance their security posture.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published