{"api_version":"1","generated_at":"2026-07-23T11:47:58+00:00","cve":"CVE-2015-1915","urls":{"html":"https://cve.report/CVE-2015-1915","api":"https://cve.report/api/cve/CVE-2015-1915.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-1915","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-1915"},"summary":{"title":"CVE-2015-1915","description":"The Endpoint Manager for Remote Control component in IBM Tivoli Endpoint Manager for Lifecycle Management 9.0.1 before IF6 and 9.1.0 before IF6 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.","state":"PUBLISHED","assigner":"ibm","published_at":"2015-05-25 00:59:10","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IV72069","name":"http://www-01.ibm.com/support/docview.wss?uid=swg1IV72069","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"IBM IV72069: SECURITY APAR:CVE-2015-1915 ENCRYPTED SESSION (SSL) COOKIE ISSUE IN IBM ENDPOINT MANAGER FOR REMOTE CONTROL - United States","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/74193","name":"http://www.securityfocus.com/bid/74193","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM Endpoint Manager for Remote Control CVE-2015-1915 Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21882571","name":"http://www-01.ibm.com/support/docview.wss?uid=swg21882571","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"IBM Security Bulletin: Missing Secure Attribute in Encrypted Session (SSL) Cookie affects IBM Endpoint Manager for Remote Control - United States","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-1915","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-1915","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"1915","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"endpoint_manager_family","cpe6":"9.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"1915","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"endpoint_manager_family","cpe6":"9.1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T04:54:16.656Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"74193","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/74193"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21882571"},{"name":"IV72069","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IV72069"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-04-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Endpoint Manager for Remote Control component in IBM Tivoli Endpoint Manager for Lifecycle Management 9.0.1 before IF6 and 9.1.0 before IF6 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-11-28T20:57:01.000Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"name":"74193","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/74193"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21882571"},{"name":"IV72069","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IV72069"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","ID":"CVE-2015-1915","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Endpoint Manager for Remote Control component in IBM Tivoli Endpoint Manager for Lifecycle Management 9.0.1 before IF6 and 9.1.0 before IF6 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"74193","refsource":"BID","url":"http://www.securityfocus.com/bid/74193"},{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg21882571","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21882571"},{"name":"IV72069","refsource":"AIXAPAR","url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IV72069"}]}}}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2015-1915","datePublished":"2015-05-25T00:00:00.000Z","dateReserved":"2015-02-19T00:00:00.000Z","dateUpdated":"2024-08-06T04:54:16.656Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-05-25 00:59:10","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:endpoint_manager_family:9.0.1:*:*:*:*:*:*:*","matchCriteriaId":"FAB39C38-DE06-4A57-95C0-A8C27670668F"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:endpoint_manager_family:9.1.0:*:*:*:*:*:*:*","matchCriteriaId":"2C35B79C-3653-4948-B5D6-5F387707A210"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"1915","Ordinal":"1","Title":"CVE-2015-1915","CVE":"CVE-2015-1915","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"1915","Ordinal":"1","NoteData":"The Endpoint Manager for Remote Control component in IBM Tivoli Endpoint Manager for Lifecycle Management 9.0.1 before IF6 and 9.1.0 before IF6 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.","Type":"Description","Title":"CVE-2015-1915"},{"CveYear":"2015","CveId":"1915","Ordinal":"2","NoteData":"2015-05-24","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"1915","Ordinal":"3","NoteData":"2016-11-28","Type":"Other","Title":"Modified"}]}}}