Aller au contenu

Fiche vulnérabilité

CVE-2025-36249 : faille moyenne ibm jazz for service management (CVSS 5.3)

Description

IBM Jazz for Service Management 1.1.3.0 through 1.1.3.25 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.

En bref

Sévérité
Moyenne (CVSS 5.3)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
31 oct. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • ibm jazz for service management

Références

Rechercher une autre vulnérabilité dans la base CVE