Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have HttpOnly flag. This allows malicious javascript to steal it.
The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sentinel_ldk | Gemalto | * | 7.92 (excluding) |