Description
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 198755.
CVSS breakdown
CVSS 3.0
Attack Vector
Network
Privileges Required
None
Scope
Unchanged
Integrity
None
Confidentiality
Low
Availability
None
User Interaction
None
Attack Complexity
High
E
Unchanged
RL
O
RC
Changed
Affected products
- ibm / planning_analytics2.0 – 2.0
Updated 16m ago · 8 sources