IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 228587.
References
Configurations
No configuration.
History
30 Jul 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-30 17:15
Updated : 2024-07-30 17:15
NVD link : CVE-2022-33167
Mitre link : CVE-2022-33167
CVE.ORG link : CVE-2022-33167
JSON object : View
Products Affected
No product.
CWE
CWE-1004
Sensitive Cookie Without 'HttpOnly' Flag