CVE-2015-5183
published 2017-09-25CVE-2015-5183: Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ.
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
2.20%
80.6th percentile
Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | amq | < 6.3 | 6.3 |
| redhat | jboss_a-mq | — | — |
| redhat | jboss_enterprise_web_server | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ
vendor_redhat·2015-10-06·CVSS 7.5
CVE-2015-5183 [HIGH] Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ
Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ
Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ.
It was found that Hawtio console does not set HTTPOnly or Secure attributes on cookies. An attacker could use this flaw to rerieve an authenticated user's SessionID, and possibly conduct further attacks with the permissions of the authenticated user.
Statement: This flaw affects only the Red Hat AMQ Product, and does not impact Apache ActiveMQ.
Package: Hawtio (Red Hat AMQ Broker 7) - Affected
GHSA
GHSA-mr89-3f5g-76w3: Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ
ghsa_unreviewed·2022-05-13
CVE-2015-5183 [HIGH] GHSA-mr89-3f5g-76w3: Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ
Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ.
No detection rules found.
No public exploits indexed.
http://www.securitytracker.com/id/1041750https://access.redhat.com/errata/RHSA-2018:2840https://bugzilla.redhat.com/show_bug.cgi?id=1249182https://lists.apache.org/thread.html/9e3391878c6840b294155f7ba6ccb47586e317f85c1bbd15c4608bd0%40%3Cdev.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r51c60b28154fe7b634e5f5b7a7fc7f6f060487b39a7b5e95e2c32047%40%3Cdev.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r63480b481eb5922465da102d97d0906d8823687f99ef3255ebc32be8%40%3Cdev.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/rb280e767ab199767e07a367f287ba08a9692fa76e2da4a20d50d07c4%40%3Cdev.activemq.apache.org%3Ehttp://www.securitytracker.com/id/1041750https://access.redhat.com/errata/RHSA-2018:2840https://bugzilla.redhat.com/show_bug.cgi?id=1249182https://lists.apache.org/thread.html/9e3391878c6840b294155f7ba6ccb47586e317f85c1bbd15c4608bd0%40%3Cdev.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r51c60b28154fe7b634e5f5b7a7fc7f6f060487b39a7b5e95e2c32047%40%3Cdev.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r63480b481eb5922465da102d97d0906d8823687f99ef3255ebc32be8%40%3Cdev.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/rb280e767ab199767e07a367f287ba08a9692fa76e2da4a20d50d07c4%40%3Cdev.activemq.apache.org%3E
2017-09-25
Published