Synced 19 Jun 2026 07:34 UTC Account
← All products

CVE-2014-0905

LOW severity · CVSS 2.9 · CWE-264
2.9CVSS LOW

Summary

IBM InfoSphere BigInsights 2.0 through 2.1.2 does not set the secure flag for the LTPA cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

Impact & exploitability

Attack vectorAdjacent
Attack complexity
Privileges required
User interaction
Confidentiality impact
Integrity impactNone
Availability impactNone
Exploit probability (EPSS)1%

AV:A/AC:M/Au:N/C:P/I:N/A:N

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.