Severity
4.3MEDIUM
EPSS
0.3%
top 51.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 4
Latest updateOct 2

Description

IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDibm/websphere_extreme_scale7.1.0, 7.1.0.2, 7.1.1+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-x4vf-q922-8w98: IBM WebSphere eXtreme Scale 72022-05-17
CVEList
CVE-2015-2025: IBM WebSphere eXtreme Scale 72015-10-04

💥Exploits & PoCs

1
Exploit-DB
Microsoft Edge Windows 10 Version 1511 - Cross Site Scripting (XSS)2025-07-22

📋Vendor Advisories

15
CISA
Juniper ScreenOS Improper Authentication Vulnerability2025-10-02
Red Hat
kernel: wifi: rtl818x: Kill URBs before clearing tx status queue2025-08-19
Microsoft
Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial 2025-08-12
Microsoft
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provide2024-01-09
Microsoft
Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a denial of service (program crash) or possibly execu2020-02-11

🕵️Threat Intelligence

1
Zscaler
Adobe Flash Vulnerability CVE-2015-5119 Analysis | Zscaler2015-07-13
CVE-2015-2025 (MEDIUM CVSS 4.3) | IBM WebSphere eXtreme Scale 7.1.0 b | cvebase.io