CVE-2024-43177Improper Certificate Validation in IBM Concert

Severity
9.8CRITICALNVD
CNA5.9
EPSS
0.1%
top 77.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 22

Description

IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5ibm/concert1.0.0, 1.0.1
NVDibm/concert1.0.0, 1.0.1+1

🔴Vulnerability Details

3
CVEList
IBM Concert improper certificate validation2024-10-22
GHSA
GHSA-jrw2-3gwx-j89g: IBM Concert 12024-10-22
OSV
ruby-devise-two-factor vulnerabilities2024-10-01
CVE-2024-43177 — Improper Certificate Validation in IBM | cvebase