CVE-2022-26157

An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. The ASP.NET_Sessionid cookie is not protected by the Secure flag. This makes it prone to interception by an attacker if traffic is sent over unencrypted channels.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:cherwell:cherwell_service_management:10.2.3:*:*:*:*:*:*:*

Information

Published : 2022-02-28 08:15

Updated : 2022-03-08 10:18


NVD link : CVE-2022-26157

Mitre link : CVE-2022-26157


JSON object : View

CWE
CWE-732

Incorrect Permission Assignment for Critical Resource

Advertisement

dedicated server usa

Products Affected

cherwell

  • cherwell_service_management