VYPR
Low severity3.7NVD Advisory· Published Nov 24, 2016· Updated May 6, 2026

CVE-2016-0353

CVE-2016-0353

Description

In IBM Security Privileged Identity Manager Virtual Appliance, the session cookie lacks the secure flag, allowing capture over HTTP.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

In IBM Security Privileged Identity Manager Virtual Appliance, the session cookie lacks the secure flag, allowing capture over HTTP.

Vulnerability

IBM Security Privileged Identity Manager (ISPIM) 2.0 before version 2.0.2 FP8, when deployed as a Virtual Appliance, does not set the Secure flag for the session cookie when transmitted over an HTTPS session [1]. This means the cookie can be transmitted over unencrypted HTTP connections as well. The affected product is IBM Security Privileged Identity Manager Virtual Appliance versions up to and including 2.0.2 FP7.

Exploitation

An attacker who can intercept network traffic between the user's browser and the ISPIM Virtual Appliance can capture the session cookie if the cookie is ever transmitted over an HTTP session [1]. This requires the attacker to be positioned on the network path (e.g., on a shared network or via a Man-in-the-Middle attack) and to have the ability to monitor HTTP traffic. No authentication is required to perform the interception. The attack does not require any special user interaction beyond the user accessing the application.

Impact

Successful exploitation allows the attacker to obtain the unsecured session cookie, which can then be used to impersonate the victim's authenticated session [1]. This could lead to unauthorized access to the victim's account and the privileged identity management environment, potentially exposing sensitive information or allowing further actions within the scope of the compromised session. The CVSS v3 base score is 3.7 (Low), indicating limited confidentiality impact due to the need for network access and specific conditions.

Mitigation

IBM addressed this vulnerability in IBM Security Privileged Identity Manager version 2.0.2 FP8 [1]. Users should upgrade to version 2.0.2 FP8 or later to ensure the session cookie is marked with the Secure flag. There is no known workaround for earlier versions. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4
  • cpe:2.3:a:ibm:security_privileged_identity_manager:2.0.0:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:ibm:security_privileged_identity_manager:2.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:security_privileged_identity_manager:2.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:security_privileged_identity_manager:2.0.2:*:*:*:*:*:*:*
    • (no CPE)range: <2.0.2 FP8

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.