CVE-2015-0102
Summary
| CVE | CVE-2015-0102 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-05 18:15:00 UTC |
| Updated | 2020-02-07 19:33:00 UTC |
| Description | IBM Workflow for Bluemix does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM Security Bulletin: Authentication session cookie in IBM Workflow for Bluemix was missing Secure flag (CVE-2015-0102) - IBM PSIRT Blog | CONFIRM | www.ibm.com | Vendor Advisory |
| IBM notice: The page you requested cannot be displayed | CONFIRM | www-01.ibm.com | Broken Link |
| IBM Workflow for Bluemix CVE-2015-0102 Information Disclosure Vulnerability | MISC | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.