IBM Datacap 9.1.7, 9.1.8, and 9.1.9
does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.
does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7238443 |
![]() ![]() |
History
Tue, 01 Jul 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ibm datacap Navigator
|
|
CPEs | cpe:2.3:a:ibm:datacap_navigator:*:*:*:*:*:*:*:* | |
Vendors & Products |
Ibm datacap Navigator
|
Mon, 30 Jun 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 28 Jun 2025 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM Datacap 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. | |
Title | IBM Datacap information disclosure | |
First Time appeared |
Ibm
Ibm datacap |
|
Weaknesses | CWE-614 | |
CPEs | cpe:2.3:a:ibm:datacap:9.1.7:*:*:*:*:*:*:* cpe:2.3:a:ibm:datacap:9.1.8:*:*:*:*:*:*:* cpe:2.3:a:ibm:datacap:9.1.9:*:*:*:*:*:*:* |
|
Vendors & Products |
Ibm
Ibm datacap |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-08-24T11:38:32.866Z
Reserved: 2025-04-15T21:16:08.835Z
Link: CVE-2025-36026

Updated: 2025-06-30T13:41:35.085Z

Status : Analyzed
Published: 2025-06-28T01:15:25.153
Modified: 2025-07-01T14:22:26.260
Link: CVE-2025-36026

No data.

No data.