IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10.12.0 through 1.10.19.0 does not set the SameSite attribute for sensitive cookies which could allow an attacker to obtain sensitive information using man-in-the-middle techniques. IBM X-Force ID: 233778.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: ibm
Published: 2024-05-01T12:48:12.167Z
Updated: 2024-08-03T10:54:03.704Z
Reserved: 2022-08-16T18:42:49.432Z
Link: CVE-2022-38386
Vulnrichment
Updated: 2024-08-03T10:54:03.704Z
NVD
Status : Awaiting Analysis
Published: 2024-05-01T13:15:47.960
Modified: 2024-05-01T19:50:25.633
Link: CVE-2022-38386
Redhat
No data.