← Back

CVE-2014-3092

nvd nist
Published: Sep 12, 2014Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.6 iFix 3, 4.x before 4.0.7, and 5.x before 5.0.1; and other Rational products, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

Affected (105)

7 products
Rational Doors Next Generation
Rational Quality Manager
Rational Requirements Composer
Rational Rhapsody Design Manager
Rational Team Concert
Configuration A
105 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 4.0.0
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4
Version 4.0.5
Version 4.0.6
Version 5.0
Ibm
Version 1.0.0.1
Version 1.0
Version 4.03
Version 4.04
Version 4.05
Version 4.06
Version 5.0
Ibm
Version 2.0.0.1
Version 2.0.0.2
Version 2.0.1.1
Version 2.0.1
Version 2.0
Version 3.0.1.1
Version 3.0.1.2
Version 3.0.1.3
Version 3.0.1.4
Version 3.0.1.5
Version 3.0.1.6
Version 3.0.1
Version 3.0
Version 4.0.0.1
Version 4.0.0.2
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4
Version 4.0.5
Version 4.0.6
Version 4.0
Version 5.0
Ibm
Version 2.0.0.1
Version 2.0.0.2
Version 2.0.0.3
Version 2.0.0.4
Version 2.0
Version 3.0.1.1
Version 3.0.1.2
Version 3.0.1.3
Version 3.0.1.4
Version 3.0.1.5
Version 3.0.1.6
Version 3.0.1
Version 3.0
Version 4.0.0.1
Version 4.0.0.2
Version 4.0.0
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4
Version 4.0.5
Version 4.0.6
Version 4.0
Ibm
Version 3.0.0.1
Version 3.0.1
Version 3.0
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4
Version 4.0.5
Version 4.0.6
Version 4.0
Version 5.0
Ibm
Version 3.0.0.1
Version 3.0.0
Version 3.0.1
Version 3.0
Version 4.0.0
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4
Version 4.0.5
Version 4.0.6
Version 5.0
Ibm
Version 2.0.0.1
Version 2.0.0.2
Version 2.0
Version 3.0.1.1
Version 3.0.1.2
Version 3.0.1.3
Version 3.0.1.4
Version 3.0.1.5
Version 3.0.1.6
Version 3.0.1
Version 3.0
Version 4.0.0.1
Version 4.0.0.2
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4
Version 4.0.5
Version 4.0.6
Version 4.0
Version 5.0

References (4)

Source: psirt@us.ibm.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.