← Back
CWE-1004

42 CVEs • Abstraction: Variant • Likelihood of Exploit: Medium

Sensitive Cookie Without 'HttpOnly' Flag

The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.

JSON object

Loading...

CVEs (42)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sap
1Disclosure Management
Jun 17, 2026
Jul 14, 2020
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cookie without Http Only flag.
1Gemalto
1Sentinel Ldk
Jun 17, 2026
Jun 7, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag. This allows malicious javascript to steal it.