5
CVSSv2

CVE-2015-5183

Published: 25/09/2017 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss enterprise web server 1.0.0

redhat jboss a-mq 7

redhat amq

Vendor Advisories

Synopsis Low: Red Hat JBoss Fuse/A-MQ 63 R9 security and bug fix update Type/Severity Security Advisory: Low Topic An update is now available for Red Hat JBoss Fuse 63 and Red Hat JBoss A-MQ 63Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scori ...
Synopsis Moderate: Red Hat AMQ Broker 78 release and security update Type/Severity Security Advisory: Moderate Topic Red Hat AMQ Broker 78 is now available from the Red Hat Customer PortalRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scorin ...
Synopsis Moderate: Red Hat AMQ Broker 745 release and security update Type/Severity Security Advisory: Moderate Topic Red Hat AMQ Broker 745 is now available from the Red Hat Customer PortalRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Sc ...
Synopsis Important: Red Hat AMQ Broker 77 release and security update Type/Severity Security Advisory: Important Topic Red Hat AMQ Broker 77 is now available from the Red Hat Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Sco ...
It was found that JBoss A-MQ's Hawtio console does not set HTTPOnly or Secure attributes on cookies An attacker could use this flaw to rerieve an authenticated user's SessionID, and possibly conduct further attacks with the permissions of the authenticated user ...