← volver
CVE-2018-1480medium

CVE-2018-1480

13Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 4epss 1.1%
probabilidad de explotación
1.1%top 35% de las CVE
explotación observada
noninguna fuente lo reporta
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the 'HttpOnly' attribute on authorization tokens or session cookies. If a Cross-Site Scripting vulnerability also existed attackers may be able to get the cookie values via malicious JavaScript and then hijack the user session. IBM X-Force ID: 140762.
CVSS:3.0/A:N/AC:H/AV:N/C:L/I:N/PR:N/S:C/UI:N/E:H/RC:C/RL:O
Productos afectados
IBM · BigFix Platform