IBM PowerHA SystemMirror for i 7.4 and 7.5
does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.
does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7180036 |
![]() ![]() |
History
Fri, 20 Jun 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ibm
Ibm i Ibm powerha System Mirror |
|
CPEs | cpe:2.3:a:ibm:powerha_system_mirror:-:*:*:*:*:*:*:* cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:* cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:* |
|
Vendors & Products |
Ibm
Ibm i Ibm powerha System Mirror |
Thu, 13 Mar 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-614 |
Mon, 06 Jan 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 03 Jan 2025 22:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM PowerHA SystemMirror for i 7.4 and 7.5 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. | |
Title | IBM PowerHA SystemMirror for i information disclosure | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-03-13T15:54:02.868Z
Reserved: 2024-12-12T18:07:11.452Z
Link: CVE-2024-55897

Updated: 2025-01-06T16:16:41.600Z

Status : Analyzed
Published: 2025-01-03T23:15:08.573
Modified: 2025-06-20T18:11:09.177
Link: CVE-2024-55897

No data.

No data.