ITarian - Session cookie not protected by HttpOnly flag
Published Jun 8, 2022
7.5
HIGHCVSS 3.1
EPSS 0.82%
Description
Within the Service Desk module of the ITarian platform (SAAS and on-premise), a remote attacker can obtain sensitive information, caused by the failure to set the HTTP Only flag. A remote attacker could exploit this vulnerability to gain access to the management interface by using this vulnerability in combination with a successful Cross-Site Scripting attack on a user.
Affected products
-
- Version any versionStatusaffectedConstraints<6.35.37347.20040
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| ITarian | ITarian SaaS platform / on-premise | n/a |
|
- < 6.35.37347.20040
- < 6.35.37347.20040
-
- Version 0StatusaffectedConstraints<6.35.37347.20040
- Version
-
- Version 0StatusaffectedConstraints<6.35.37347.20040
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Itarian | On-Premise | n/a |
| ||||||
| Itarian | Saas Service Desk | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://csirt.divd.nl/CVE-2022-25151 x_refsource_CONFIRMthird-party-advisoryThird Party Advisory
- https://csirt.divd.nl/DIVD-2021-00037 x_refsource_CONFIRMrelatedThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-29894 Advisory
| Link | Providers | Tags |
|---|---|---|
| https://csirt.divd.nl/CVE-2022-25151 | x_refsource_CONFIRMthird-party-advisoryThird Party Advisory | |
| https://csirt.divd.nl/DIVD-2021-00037 | x_refsource_CONFIRMrelatedThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-29894 | Advisory |
Change history (0)
No recorded changes yet.