IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10.12.0 through 1.10.19.0 does not set the SameSite attribute for sensitive cookies which could allow an attacker to obtain sensitive information using man-in-the-middle techniques.  IBM X-Force ID:  233778.
                
            References
                    Configurations
                    No configuration.
History
                    No history.
Information
                Published : 2024-05-01 13:15
Updated : 2024-05-01 19:50
NVD link : CVE-2022-38386
Mitre link : CVE-2022-38386
CVE.ORG link : CVE-2022-38386
JSON object : View
Products Affected
                No product.
CWE
                
                    
                        
                        CWE-1275
                        
            Sensitive Cookie with Improper SameSite Attribute
