CVE Vulnerabilities

CVE-2022-38386

Sensitive Cookie with Improper SameSite Attribute

Published: May 01, 2024 | Modified: May 01, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10.12.0 through 1.10.19.0 does not set the SameSite attribute for sensitive cookies which could allow an attacker to obtain sensitive information using man-in-the-middle techniques. IBM X-Force ID: 233778.

Weakness

The SameSite attribute for sensitive cookies is not set, or an insecure value is used.

Potential Mitigations

References