Cookie Management Flaw in IBM Concert Products
CVE-2024-43177

9.8CRITICAL

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
22 October 2024

What is CVE-2024-43177?

IBM Concert versions 1.0.0 and 1.0.1 are impacted by a vulnerability that stems from improper handling of cookies lacking the SameSite attribute. This oversight may expose users to various security threats, such as cross-site request forgery (CSRF) attacks, where malicious third parties could exploit the lack of cookie restrictions to execute unauthorized actions. Organizations using these versions are advised to implement necessary mitigations and consider updates from IBM to enhance their security posture.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2024-43177 : Cookie Management Flaw in IBM Concert Products