Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Filtered by product Concert
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-43177 1 Ibm 1 Concert 2024-10-25 N/A 9.8 CRITICAL
IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.
CVE-2024-43173 1 Ibm 1 Concert 2024-10-25 N/A 3.7 LOW
IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.
CVE-2024-43180 1 Ibm 1 Concert 2024-09-20 N/A 4.3 MEDIUM
IBM Concert 1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.