CVE-2020-4780

OOTB build scripts does not set the secure attribute on session cookie which may impact IBM Curam Social Program Management 7.0.9 and 7.0,10. The purpose of the 'secure' attribute is to prevent cookies from being observed by unauthorized parties. IBM X-Force ID: 189158.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:curam_social_program_management:7.0.9.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:curam_social_program_management:7.0.10.0:*:*:*:*:*:*:*

History

21 Nov 2024, 05:33

Type Values Removed Values Added
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/189158 - VDB Entry, Vendor Advisory () https://exchange.xforce.ibmcloud.com/vulnerabilities/189158 - VDB Entry, Vendor Advisory
References () https://www.ibm.com/support/pages/node/6346581 - Vendor Advisory () https://www.ibm.com/support/pages/node/6346581 - Vendor Advisory

Information

Published : 2020-10-12 13:15

Updated : 2024-11-21 05:33


NVD link : CVE-2020-4780

Mitre link : CVE-2020-4780

CVE.ORG link : CVE-2020-4780


JSON object : View

Products Affected

ibm

  • curam_social_program_management
CWE
CWE-613

Insufficient Session Expiration