does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-52844 | IBM PowerHA SystemMirror for i 7.4 and 7.5 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7180036 |
|
Fri, 20 Jun 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibm
Ibm i Ibm powerha System Mirror |
|
| CPEs | cpe:2.3:a:ibm:powerha_system_mirror:-:*:*:*:*:*:*:* cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:* cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm i Ibm powerha System Mirror |
Thu, 13 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-614 |
Mon, 06 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 03 Jan 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM PowerHA SystemMirror for i 7.4 and 7.5 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. | |
| Title | IBM PowerHA SystemMirror for i information disclosure | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-03-13T15:54:02.868Z
Reserved: 2024-12-12T18:07:11.452Z
Link: CVE-2024-55897
Updated: 2025-01-06T16:16:41.600Z
Status : Analyzed
Published: 2025-01-03T23:15:08.573
Modified: 2025-06-20T18:11:09.177
Link: CVE-2024-55897
No data.
OpenCVE Enrichment
No data.
EUVD