CVE Vulnerabilities

CVE-2023-46179

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

Published: Mar 15, 2024 | Modified: Mar 19, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Sterling Secure Proxy 6.0.3 and 6.1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 269683.

Weakness

The Secure attribute for sensitive cookies in HTTPS sessions is not set, which could cause the user agent to send those cookies in plaintext over an HTTP session.

Affected Software

Name Vendor Start Version End Version
Sterling_secure_proxy Ibm 6.0.3 (including) 6.0.3 (including)
Sterling_secure_proxy Ibm 6.1.0 (including) 6.1.0 (including)

Potential Mitigations

References