CVE Vulnerabilities

CVE-2015-1993

Published: Nov 08, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not set the secure flag for unspecified cookies in an https session, which makes it easier for remote attackers to capture these cookies by intercepting their transmission within an http session.

Affected Software

NameVendorStart VersionEnd Version
Security_qradar_incident_forensicsIbm7.2.0 (including)7.2.0 (including)
Security_qradar_incident_forensicsIbm7.2.1 (including)7.2.1 (including)
Security_qradar_incident_forensicsIbm7.2.2 (including)7.2.2 (including)
Security_qradar_incident_forensicsIbm7.2.3 (including)7.2.3 (including)
Security_qradar_incident_forensicsIbm7.2.4 (including)7.2.4 (including)
Security_qradar_incident_forensicsIbm7.2.5 (including)7.2.5 (including)

References