IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.6 iFix 3, 4.x before 4.0.7, and 5.x before 5.0.1; and other Rational products, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

Project Subscriptions

Vendors Products
Rational Doors Next Generation Subscribe
Rational Engineering Lifecycle Manager Subscribe
Rational Quality Manager Subscribe
Rational Requirements Composer Subscribe
Rational Rhapsody Design Manager Subscribe
Rational Software Architect Design Manager Subscribe
Rational Team Concert Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2014-3113 IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.6 iFix 3, 4.x before 4.0.7, and 5.x before 5.0.1; and other Rational products, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2024-08-06T10:35:55.834Z

Reserved: 2014-04-29T00:00:00

Link: CVE-2014-3092

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2014-09-12T01:55:06.810

Modified: 2025-04-12T10:46:40.837

Link: CVE-2014-3092

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses