IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 171825.
View Full Alert
Related Posts
-
Move Your Data Center to the CloudThis was a very popular CIO Group Virtual Roundtable from last year. It has received well over 10,000 views. I love the quality of Garry’s research and passion he has…
Password Management is Being Disrupted NowDuring a recent security assessment RedZone asked the customer a standard question about password management: “Are your passwords being changed on this outsourced web server?” With Heartbleed, WordPress, and SSL vulnerabilities,…