2.9
CVSSv2

CVE-2014-0905

Published: 17/08/2014 Updated: 29/08/2017
CVSS v2 Base Score: 2.9 | Impact Score: 2.9 | Exploitability Score: 5.5
VMScore: 258
Vector: AV:A/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

IBM InfoSphere BigInsights 2.0 up to and including 2.1.2 does not set the secure flag for the LTPA cookie in an https session, which makes it easier for remote malicious users to capture this cookie by intercepting its transmission within an http session.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm infosphere biginsights 2.1.2.0

ibm infosphere biginsights 2.0.0.0

ibm infosphere biginsights 2.1.0.0

ibm infosphere biginsights 2.1.1.0