Vulnerability Bulletins |
IBM Security Bulletin: IBM QRadar SIEM is vulnerable to a client side scripting attack due to a missing HTTPOnly flag on a cookie. (CVE-2015-1994) |
|
| Affected software | IBM |
|
One of the cookies used for user authorization is missing the HTTPOnly Attribute which allows attackers leveraging a Cross-Site Scripting vulnerability to obtain the cookie value and then perform a session hijacking attack. CVE(s): CVE-2015-1994Affected product(s) and affected version(s):· IBM QRadar 7.1 MR2 · IBM QRadar 7.2.n Refer to the following reference URLs for remediation and additional vulnerability details:Source Bulletin: More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_qradar_siem_is_vulnerable_to_a_client_side_scripting_attack_due_to_a_missing_httponly_flag_on_a_cookie_cve_2015_1994?lang=en_us |
|






