4.3
CVSSv2

CVE-2014-0174

Published: 11/07/2014 Updated: 15/07/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote malicious users to obtain potentially sensitive information via script access to this cookie.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise mrg 2.5

Vendor Advisories

It was found that Cumin did not set the HttpOnly flag on session cookies This could allow a malicious script to access the session cookie ...