CVE-2021-38977
Summary
| CVE | CVE-2021-38977 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-15 16:15:00 UTC |
| Updated | 2022-07-12 17:42:00 UTC |
| Description | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 212782. |
Risk And Classification
Problem Types: CWE-311
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Ibm | Aix | - | All | All | All |
| Application | Ibm | Security Guardium Key Lifecycle Manager | 4.1.0 | All | All | All |
| Application | Ibm | Security Guardium Key Lifecycle Manager | 4.1.0.1 | All | All | All |
| Application | Ibm | Security Guardium Key Lifecycle Manager | 4.1.1 | All | All | All |
| Application | Ibm | Security Key Lifecycle Manager | 4.1.0 | All | All | All |
| Application | Ibm | Security Key Lifecycle Manager | 4.1.0.1 | All | All | All |
| Application | Ibm | Security Key Lifecycle Manager | 4.1.1 | All | All | All |
| Application | Ibm | Security Key Lifecycle Manager | All | All | All | All |
| Application | Ibm | Security Key Lifecycle Manager | All | All | All | All |
| Application | Ibm | Security Key Lifecycle Manager | All | All | All | All |
| Operating System | Linux | Linux Kernel | - | All | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | VDB Entry, Vendor Advisory |
| Security Bulletin: Missing cookie secure attribute in IBM Security Guardium Key Lifecycle Manager (CVE-2021-38977) | CONFIRM | www.ibm.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.