CVE Vulnerabilities

CVE-2014-4830

Published: Oct 19, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

Affected Software

NameVendorStart VersionEnd Version
Qradar_security_information_and_event_managerIbm7.1.0 (including)7.1.0 (including)
Qradar_security_information_and_event_managerIbm7.2.0 (including)7.2.0 (including)

References