Show plain JSON{"id": "CVE-2018-1484", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Secondary", "source": "psirt@us.ibm.com", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 3.7, "attackVector": "NETWORK", "baseSeverity": "LOW", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "HIGH", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "LOW"}, "impactScore": 1.4, "exploitabilityScore": 2.2}, {"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 3.7, "attackVector": "NETWORK", "baseSeverity": "LOW", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "HIGH", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "LOW"}, "impactScore": 1.4, "exploitabilityScore": 2.2}]}, "published": "2018-12-12T16:29:01.137", "references": [{"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/140969", "tags": ["VDB Entry", "Vendor Advisory"], "source": "psirt@us.ibm.com"}, {"url": "https://www.ibm.com/support/docview.wss?uid=ibm10733605", "tags": ["Vendor Advisory"], "source": "psirt@us.ibm.com"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/140969", "tags": ["VDB Entry", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://www.ibm.com/support/docview.wss?uid=ibm10733605", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-384"}]}], "descriptions": [{"lang": "en", "value": "IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 140969."}, {"lang": "es", "value": "IBM BigFix Platform, desde la versi\u00f3n 9.2.0 hasta la 9.2.14 y de la versi\u00f3n 9.5 hasta la 9.5.9, no establece el atributo \"secure\" en los tokens de autorizaci\u00f3n o en las cookies de sesi\u00f3n. Los atacantes podr\u00edan ser capaces de obtener el valor de las cookies mediante el env\u00edo de un enlace http:// a un usuario o colocando este enlace en un sitio que visita el usuario. La cookie se enviar\u00e1 al enlace inseguro y el atacante podr\u00e1 entonces obtener el valor de la cookie rastreando el tr\u00e1fico. IBM X-Force ID: 140969."}], "lastModified": "2024-11-21T03:59:54.593", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:ibm:bigfix_platform:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "41250DB2-F886-4105-B7E7-DF9D698C6029", "versionEndIncluding": "9.2.14", "versionStartIncluding": "9.2.0"}, {"criteria": "cpe:2.3:a:ibm:bigfix_platform:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AB2C8863-EEBD-492B-9DAE-2E5C296B0BCE", "versionEndIncluding": "9.5.9", "versionStartIncluding": "9.5"}], "operator": "OR"}]}], "sourceIdentifier": "psirt@us.ibm.com"}