does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.
No analysis available yet.
Vendor Solution
IBM strongly suggests that you address the vulnerabilities now for all the affected products/versions listed above by installing Fix. See the https://www.ibm.com/support/pages/node/7231588 readme for details.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19436 | IBM Datacap 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7238443 |
|
Tue, 01 Jul 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibm datacap Navigator
|
|
| CPEs | cpe:2.3:a:ibm:datacap_navigator:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm datacap Navigator
|
Mon, 30 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 28 Jun 2025 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Datacap 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. | |
| Title | IBM Datacap information disclosure | |
| First Time appeared |
Ibm
Ibm datacap |
|
| Weaknesses | CWE-614 | |
| CPEs | cpe:2.3:a:ibm:datacap:9.1.7:*:*:*:*:*:*:* cpe:2.3:a:ibm:datacap:9.1.8:*:*:*:*:*:*:* cpe:2.3:a:ibm:datacap:9.1.9:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm datacap |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-08-24T11:38:32.866Z
Reserved: 2025-04-15T21:16:08.835Z
Link: CVE-2025-36026
Updated: 2025-06-30T13:41:35.085Z
Status : Analyzed
Published: 2025-06-28T01:15:25.153
Modified: 2025-07-01T14:22:26.260
Link: CVE-2025-36026
No data.
OpenCVE Enrichment
No data.
EUVD