Session Cookie Vulnerability in IBM Jazz for Service Management
CVE-2025-36011
4.3MEDIUM
What is CVE-2025-36011?
IBM Jazz for Service Management versions 1.1.3.0 through 1.1.3.24 are vulnerable due to the lack of a secure attribute on authorization tokens and session cookies. This flaw may allow attackers to intercept cookie values by exploiting unsecured links. If a user clicks on a malicious link, their session cookies could be transmitted over an insecure channel, enabling attackers to capture sensitive information and potentially gain unauthorized access to the user's session.
Affected Version(s)
Jazz for Service Management 1.1.3.0 <= 1.1.3.24