IBM DataPower Gateway appliances with firmware 6.x before 6.0.0.17, 6.0.1.x before 6.0.1.17, 7.x before 7.0.0.10, 7.1.0.x before 7.1.0.7, and 7.2.x before 7.2.0.1 do not set the secure flag for unspecified cookies in an https session, which makes it easier for remote attackers to capture these cookies by intercepting their transmission within an http session.
                
            References
                    | Link | Resource | 
|---|---|
| http://www-01.ibm.com/support/docview.wss?uid=swg21969342 | Vendor Advisory | 
| http://www-01.ibm.com/support/docview.wss?uid=swg1IT10279 | 
Configurations
                    Configuration 1 (hide)
                                
                                
  | 
                        
Information
                Published : 2015-11-13 19:59
Updated : 2015-11-16 11:20
NVD link : CVE-2015-7427
Mitre link : CVE-2015-7427
JSON object : View
CWE
                
                    
                        
                        CWE-200
                        
            Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
                ibm
- datapower_gateway
 


