← Back

CVE-2014-0634

nvd nist
Published: Apr 1, 2014Modified: May 6, 2026

JSON object

Loading...
6.0
Vector
AV:N/AC:M/Au:S/C:P/I:P/A:P
Exploitability: 6.8 / Impact: 6.4
Source: NVD

Description

EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

Affected (5)

1 product
Vplex Geosynchrony
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Emc
Version 4.0
Version 5.0
Version 5.1
Version 5.2.1
Version 5.2

References (2)

Timeline

No history available yet.