Description
IBM Lotus Notes 8.5.x before 8.5.3 FP3 does not include the HTTPOnly flag in a Set-Cookie header for a web-application cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, aka SPRs JMAS7TRNLN and SRAO8U3Q68.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2012-4771 | IBM Lotus Notes 8.5.x before 8.5.3 FP3 does not include the HTTPOnly flag in a Set-Cookie header for a web-application cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, aka SPRs JMAS7TRNLN and SRAO8U3Q68. |
References
History
No history.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-08-06T20:50:17.337Z
Reserved: 2012-09-06T00:00:00.000Z
Link: CVE-2012-4846
No data.
Status : Deferred
Published: 2012-12-19T11:55:54.750
Modified: 2025-04-11T00:51:21.963
Link: CVE-2012-4846
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD