CVE-2020-4780
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/10/2020
Last modified:
26/10/2020
Description
OOTB build scripts does not set the secure attribute on session cookie which may impact IBM Curam Social Program Management 7.0.9 and 7.0,10. The purpose of the 'secure' attribute is to prevent cookies from being observed by unauthorized parties. IBM X-Force ID: 189158.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ibm:curam_social_program_management:7.0.9.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:curam_social_program_management:7.0.10.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



