CVE Vulnerabilities

CVE-2012-5936

Published: Jul 03, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

Affected Software

NameVendorStart VersionEnd Version
Sterling_b2b_integratorIbm5.1 (including)5.1 (including)
Sterling_b2b_integratorIbm5.2 (including)5.2 (including)
Sterling_file_gatewayIbm2.1 (including)2.1 (including)
Sterling_file_gatewayIbm2.2 (including)2.2 (including)

References