PT-2023-22224 · Ibm · Ibm Sterling Connect:Express For Unix
CVE-2023-29259
·
Publicado
2023-07-19
·
Atualizado
2023-07-28
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Sterling Connect:Express for UNIX version 1.5
Description
The issue is related to the use of cookies without the SameSite attribute in the browser UI, making it vulnerable to certain attacks.
Recommendations
For IBM Sterling Connect:Express for UNIX version 1.5, consider configuring cookies to include the SameSite attribute to mitigate the risk of exploitation. As a temporary workaround, restrict access to sensitive operations that rely on cookies until a proper fix is applied.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ibm Sterling Connect:Express For Unix