5
CVE-2009-3584
- EPSS 0.32%
- Published 23.12.2009 18:30:00
- Last modified 09.04.2025 00:30:58
- Source cve@mitre.org
- CVE-Watchlists
- Open
SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Data is provided by the National Vulnerability Database (NVD)
Sql-ledger ≫ Sql-ledger Version2.8.24
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
| Type | Source | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.32% | 0.519 |
| Source | Base Score | Exploit Score | Impact Score | Vector string |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|