5
CVE-2015-1993
- EPSS 0.23%
- Veröffentlicht 08.11.2015 22:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not set the secure flag for unspecified cookies in an https session, which makes it easier for remote attackers to capture these cookies by intercepting their transmission within an http session.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Security Qradar Incident Forensics Version7.2.0
Ibm ≫ Security Qradar Incident Forensics Version7.2.1
Ibm ≫ Security Qradar Incident Forensics Version7.2.2
Ibm ≫ Security Qradar Incident Forensics Version7.2.3
Ibm ≫ Security Qradar Incident Forensics Version7.2.4
Ibm ≫ Security Qradar Incident Forensics Version7.2.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.422 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|