Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
IBM PowerHA SystemMirror for i information disclosure
Vulnerability Description
IBM PowerHA SystemMirror for i 7.4 and 7.5 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Vulnerability Type
N/A
Vulnerability Title
IBM PowerHA SystemMirror 安全漏洞
Vulnerability Description
IBM PowerHA SystemMirror是美国国际商业机器(IBM)公司的一个高可用性集群多处理程序。 IBM PowerHA SystemMirror 7.4版本和7.5版本存在安全漏洞。攻击者利用该漏洞可以通过窥探流量来获取 cookie 值。
CVSS Information
N/A
Vulnerability Type
N/A