{"api_version":"1","generated_at":"2026-07-23T10:34:27+00:00","cve":"CVE-2019-4214","urls":{"html":"https://cve.report/CVE-2019-4214","api":"https://cve.report/api/cve/CVE-2019-4214.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-4214","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-4214"},"summary":{"title":"CVE-2019-4214","description":"IBM SmartCloud Analytics 1.3.1 through 1.3.5 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 159185.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2019-11-22 16:15:00","updated_at":"2020-08-24 17:37:00"},"problem_types":["CWE-311","CWE-732"],"metrics":[],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/159185","name":"ibm-smartcloud-cve20194214-info-disc (159185)","refsource":"XF","tags":["VDB Entry","Vendor Advisory"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.ibm.com/support/pages/node/1110171","name":"https://www.ibm.com/support/pages/node/1110171","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Security Bulletin: Log Analysis is vulnerable to a client side scripting attack due to missing HTTPOnly and Secure attribute in the cookie","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-4214","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-4214","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"4214","vulnerable":"1","versionEndIncluding":"1.3.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"smartcloud_analytics_log_analysis","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_format":"MITRE","impact":{"cvssv3":{"BM":{"C":"L","A":"N","SCORE":"3.700","UI":"N","PR":"N","AC":"H","S":"U","I":"N","AV":"N"},"TM":{"E":"U","RC":"C","RL":"O"}}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Obtain Information"}]}]},"description":{"description_data":[{"value":"IBM SmartCloud Analytics 1.3.1 through 1.3.5 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 159185.","lang":"eng"}]},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"version":{"version_data":[{"version_value":"1.3.1"},{"version_value":"1.3.2"},{"version_value":"1.3.3"},{"version_value":"1.3.4"},{"version_value":"1.3.5"}]},"product_name":"SmartCloud Analytics"}]},"vendor_name":"IBM"}]}},"CVE_data_meta":{"STATE":"PUBLIC","DATE_PUBLIC":"2019-11-21T00:00:00","ID":"CVE-2019-4214","ASSIGNER":"psirt@us.ibm.com"},"data_version":"4.0","data_type":"CVE","references":{"reference_data":[{"title":"IBM Security Bulletin 1110171 (SmartCloud Analytics)","refsource":"CONFIRM","name":"https://www.ibm.com/support/pages/node/1110171","url":"https://www.ibm.com/support/pages/node/1110171"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/159185","name":"ibm-smartcloud-cve20194214-info-disc (159185)","refsource":"XF","title":"X-Force Vulnerability Report"}]}},"nvd":{"publishedDate":"2019-11-22 16:15:00","lastModifiedDate":"2020-08-24 17:37:00","problem_types":["CWE-311","CWE-732"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW"},"exploitabilityScore":2.2,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:smartcloud_analytics_log_analysis:*:*:*:*:*:*:*:*","versionStartIncluding":"1.3.1","versionEndIncluding":"1.3.5","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"4214","Ordinal":"141825","Title":"CVE-2019-4214","CVE":"CVE-2019-4214","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"4214","Ordinal":"1","NoteData":"IBM SmartCloud Analytics 1.3.1 through 1.3.5 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 159185.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"4214","Ordinal":"2","NoteData":"2019-11-22","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"4214","Ordinal":"3","NoteData":"2019-11-22","Type":"Other","Title":"Modified"}]}}}