Cookie Management Flaw in IBM Concert Products
CVE-2024-43177

9.8CRITICAL

Key Information:

Vendor
IBM
Status
Vendor
CVE Published:
22 October 2024

Summary

IBM Concert versions 1.0.0 and 1.0.1 are impacted by a vulnerability that stems from improper handling of cookies lacking the SameSite attribute. This oversight may expose users to various security threats, such as cross-site request forgery (CSRF) attacks, where malicious third parties could exploit the lack of cookie restrictions to execute unauthorized actions. Organizations using these versions are advised to implement necessary mitigations and consider updates from IBM to enhance their security posture.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.