{"api_version":"1","generated_at":"2026-07-23T04:03:46+00:00","cve":"CVE-2015-0102","urls":{"html":"https://cve.report/CVE-2015-0102","api":"https://cve.report/api/cve/CVE-2015-0102.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-0102","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-0102"},"summary":{"title":"CVE-2015-0102","description":"IBM Workflow for Bluemix does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2020-02-05 18:15:00","updated_at":"2020-02-07 19:33:00"},"problem_types":["CWE-287"],"metrics":[],"references":[{"url":"https://www.ibm.com/blogs/psirt/ibm-security-bulletin-authentication-session-cookie-in-ibm-workflow-for-bluemix-was-missing-secure-flag-cve-2015-0102/","name":"https://www.ibm.com/blogs/psirt/ibm-security-bulletin-authentication-session-cookie-in-ibm-workflow-for-bluemix-was-missing-secure-flag-cve-2015-0102/","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"IBM Security Bulletin: Authentication session cookie in IBM Workflow for Bluemix was missing Secure flag (CVE-2015-0102) - IBM PSIRT Blog","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21694941","name":"http://www-01.ibm.com/support/docview.wss?uid=swg21694941","refsource":"CONFIRM","tags":["Broken Link"],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"410"},{"url":"http://www.securityfocus.com/bid/74220","name":"http://www.securityfocus.com/bid/74220","refsource":"MISC","tags":["Third Party Advisory","VDB Entry"],"title":"IBM Workflow for Bluemix CVE-2015-0102 Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-0102","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-0102","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"102","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"workflow","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"bluemix","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"102","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"workflow","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"bluemix","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","ID":"CVE-2015-0102","STATE":"PUBLIC"},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"IBM Workflow for Bluemix does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Other"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"IBM","product":{"product_data":[{"product_name":"Workflow for Bluemix","version":{"version_data":[{"version_value":"unknown"}]}}]}}]}},"references":{"reference_data":[{"refsource":"CONFIRM","name":"http://www-01.ibm.com/support/docview.wss?uid=swg21694941","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21694941"},{"refsource":"MISC","name":"http://www.securityfocus.com/bid/74220","url":"http://www.securityfocus.com/bid/74220"},{"refsource":"CONFIRM","name":"https://www.ibm.com/blogs/psirt/ibm-security-bulletin-authentication-session-cookie-in-ibm-workflow-for-bluemix-was-missing-secure-flag-cve-2015-0102/","url":"https://www.ibm.com/blogs/psirt/ibm-security-bulletin-authentication-session-cookie-in-ibm-workflow-for-bluemix-was-missing-secure-flag-cve-2015-0102/"}]}},"nvd":{"publishedDate":"2020-02-05 18:15:00","lastModifiedDate":"2020-02-07 19:33:00","problem_types":["CWE-287"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.1,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.2},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:workflow:-:*:*:*:*:bluemix:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"102","Ordinal":"76126","Title":"CVE-2015-0102","CVE":"CVE-2015-0102","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"102","Ordinal":"1","NoteData":"IBM Workflow for Bluemix does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.","Type":"Description","Title":null},{"CveYear":"2015","CveId":"102","Ordinal":"2","NoteData":"2020-02-05","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"102","Ordinal":"3","NoteData":"2020-02-05","Type":"Other","Title":"Modified"}]}}}