PT-2023-22224 · Ibm · Ibm Sterling Connect:Express For Unix

CVE-2023-29259

·

Publicado

2023-07-19

·

Atualizado

2023-07-28

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Sterling Connect:Express for UNIX version 1.5
Description The issue is related to the use of cookies without the SameSite attribute in the browser UI, making it vulnerable to certain attacks.
Recommendations For IBM Sterling Connect:Express for UNIX version 1.5, consider configuring cookies to include the SameSite attribute to mitigate the risk of exploitation. As a temporary workaround, restrict access to sensitive operations that rely on cookies until a proper fix is applied.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-29259

Produtos afetados

Ibm Sterling Connect:Express For Unix