CVE-2016-6344
published 2016-09-07CVE-2016-6344: Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes it easier for remote attackers to…
PriorityP424medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
2.19%
80.4th percentile
Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes it easier for remote attackers to obtain potentially sensitive information via script access to the cookies.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_bpm_suite | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jhjx-rgjj-x5xp: Red Hat JBoss BPM Suite 6
ghsa_unreviewed·2022-05-14
CVE-2016-6344 [MEDIUM] CWE-200 GHSA-jhjx-rgjj-x5xp: Red Hat JBoss BPM Suite 6
Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes it easier for remote attackers to obtain potentially sensitive information via script access to the cookies.
Red Hat
JBoss bpms 6.3.x cookie does not set httponly
vendor_redhat·2016-08-31·CVSS 5.3
CVE-2016-6344 [MEDIUM] CWE-20 JBoss bpms 6.3.x cookie does not set httponly
JBoss bpms 6.3.x cookie does not set httponly
Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes it easier for remote attackers to obtain potentially sensitive information via script access to the cookies.
It was discovered that JBoss BRMS 6 and BPM Suite 6 are not setting HttpOnly flags on sensitive cookies. Remote attackers can access these cookies by using client-side scripts, usually through XSS.
Package: dashbuilder (Red Hat BPM Suite 6) - Affected
Package: dashbuilder (Red Hat JBoss BRMS 6) - Affected
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2017-0248.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0249.htmlhttp://www.securityfocus.com/bid/92714https://bugzilla.redhat.com/show_bug.cgi?id=1371807http://rhn.redhat.com/errata/RHSA-2017-0248.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0249.htmlhttp://www.securityfocus.com/bid/92714https://bugzilla.redhat.com/show_bug.cgi?id=1371807
2016-09-07
Published