← Back
CWE-1004

44 CVEs • Abstraction: Variant • Likelihood of Exploit: Medium

Sensitive Cookie Without 'HttpOnly' Flag

The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.

JSON object

Loading...

CVEs (44)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pepperl Fuchs
2Wha Gw F2d2 0 As Z2 Eth.eip Firmware
Wha Gw F2d2 0 As Z2 Eth Firmware
Jun 17, 2026
Aug 31, 2021
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 and 3.0.9 the HttpOnly attribute is not set on a cookie. This allows the cookie's value to be read or set by client-side JavaScript.
1Synology
1Router Manager
Jun 17, 2026
Oct 29, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via...Show more
Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.Show less
1Sap
1Disclosure Management
Jun 17, 2026
Jul 14, 2020
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cookie without Http Only flag.
1Gemalto
1Sentinel Ldk
Jun 17, 2026
Jun 7, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag. This allows malicious javascript to steal it.