CVE-2016-0351
published 2018-02-21CVE-2016-0351: IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 does not set the secure flag for the session cookie in an HTTPS session…
PriorityP414low3.7CVSS 3.0
AVNACHPRNUINSUCLINAN
EPSS
1.05%
60.3th percentile
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 does not set the secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session. IBM X-Force ID: 111890.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | security_identity_manager_virtual_appliance | — | — |
| ibm | security_identity_manager_virtual_appliance | — | — |
| ibm | security_identity_manager_virtual_appliance | — | — |
| ibm | security_identity_manager_virtual_appliance | — | — |
| ibm | security_identity_manager_virtual_appliance | — | — |
| ibm | security_identity_manager_virtual_appliance | — | — |
| ibm | security_identity_manager_virtual_appliance | — | — |
CVSS provenance
nvdv3.03.7LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-1906 Kubernetes api server: build config to a strategy that isn't allowed by policy
bugzilla·2016-01-12·CVSS 9.8
CVE-2016-1906 [CRITICAL] CVE-2016-1906 Kubernetes api server: build config to a strategy that isn't allowed by policy
CVE-2016-1906 Kubernetes api server: build config to a strategy that isn't allowed by policy
Kubernetes api server: build config to a strategy that isn't allowed by policy
External reference:
https://github.com/openshift/origin/issues/6556
https://github.com/openshift/origin/pull/6576
Discussion:
*** Bug 1298128 has been marked as a duplicate of this bug. ***
---
This issue has been addressed in the following products:
RHEL 7 Version of OpenShift Enterprise 3.1
Via RHSA-2016:0070 https://access.redhat.com/errata/RHSA-2016:0070
---
This issue has been addressed in the following products:
RHEL 7 Version of OpenShift Enterprise 3.0
Via RHSA-2016:0351 https://access.redhat.com/errata/RHSA-2016:0351
Bugzilla
CVE-2016-1905 Kubernetes api server: patch operation should use patched object to check admission control
bugzilla·2016-01-12·CVSS 7.7
CVE-2016-1905 [HIGH] CVE-2016-1905 Kubernetes api server: patch operation should use patched object to check admission control
CVE-2016-1905 Kubernetes api server: patch operation should use patched object to check admission control
Kubernetes api server: patch operation should use patched object to check
admission control
External reference:
https://github.com/kubernetes/kubernetes/issues/19479
Discussion:
Upstream patch:
https://github.com/deads2k/kubernetes/commit/d1e258afcf837cf70522c2950bb0aef593da9c3e
---
*** Bug 1298116 has been marked as a duplicate of this bug. ***
---
This issue has been addressed in the following products:
RHEL 7 Version of OpenShift Enterprise 3.1
Via RHSA-2016:0070 https://access.redhat.com/errata/RHSA-2016:0070
---
This issue has been addressed in the following products:
RHEL 7 Version of OpenShift Enterprise 3.0
Via RHSA-2016:0351 https://access.redhat.com/errata/RHSA
2018-02-21
Published