CVE-2015-1993
Last modified
CVE-2015-1993 is a vulnerability of currently unknown severity. IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not set the secure flag for unspecified cookies in an https session, which makes it easier for remote attackers to capture these cookies by intercepting their transmission within an http session.. EPSS estimates a 1.21% chance of exploitation in the next 30 days.
Description
IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not set the secure flag for unspecified cookies in an https session, which makes it easier for remote attackers to capture these cookies by intercepting their transmission within an http session.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Security Qradar Incident Forensics | 7.2.0 |
| Ibm | Security Qradar Incident Forensics | 7.2.1 |
| Ibm | Security Qradar Incident Forensics | 7.2.2 |
| Ibm | Security Qradar Incident Forensics | 7.2.3 |
| Ibm | Security Qradar Incident Forensics | 7.2.4 |
| Ibm | Security Qradar Incident Forensics | 7.2.5 |
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21968270Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21968270Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-1993?
How severe is CVE-2015-1993?
How do I fix CVE-2015-1993?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-1987IBM MQ Light before 1.0.0.2 allows remote attackers to cause…
- CVE-2015-1988Cross-site scripting (XSS) vulnerability in IBM Tivoli Stora…
- CVE-2015-1989SQL injection vulnerability in IBM Security QRadar Incident …
- CVE-2015-1990Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2015-1991Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2015-1992IBM Systems Director 5.2.x, 6.1.x, 6.2.0.x, 6.2.1.x, 6.3.0.0…
- CVE-2015-1994IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Pa…
- CVE-2015-1995Multiple cross-site scripting (XSS) vulnerabilities in IBM S…
- CVE-2015-1996IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Pa…
- CVE-2015-1997Cross-site request forgery (CSRF) vulnerability in IBM Secur…
- CVE-2015-1999IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Pa…
- CVE-2015-2000The Jumio SDK before 1.5.0 for Android might allow attackers…
Are you affected by CVE-2015-1993?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
