CWE-1004
44 CVEs • Abstraction: Variant • Likelihood of Exploit: Medium
Sensitive Cookie Without 'HttpOnly' Flag
The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.
CVEs (44)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Pepperl Fuchs 2Wha Gw F2d2 0 As Z2 Eth.eip Firmware Wha Gw F2d2 0 As Z2 Eth FirmwareJun 17, 2026 Aug 31, 2021 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 and 3.0.9 the HttpOnly attribute is not set on a cookie. This allows the cookie's value to be read or set by client-side JavaScript. |
Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via...Show more |
Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cookie without Http Only flag. |
Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag. This allows malicious javascript to steal it. |