Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not set the secure flag for unspecified cookies in an https session, which makes it easier for remote attackers to capture these cookies by intercepting their transmission within an http session.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM Security QRadar Incident Forensics 安全漏洞
Vulnerability Description
IBM Security QRadar Incident Forensics是美国IBM公司的一套安全取证调查软件。该软件支持对疑似恶意网络安全事件进行深入取证调查,及修复网络安全漏洞。 IBM Security QRadar Incident Forensics 7.2.5 Patch 5之前7.2.x版本中存在安全漏洞,该漏洞源于程序没有为https会话中的cookie设置安全标志。远程攻击者可通过截取http会话中传输利用该漏洞捕获该cookie。
CVSS Information
N/A
Vulnerability Type
N/A