VYPR
Medium severity5.3NVD Advisory· Published Oct 12, 2020· Updated Jun 17, 2026

CVE-2020-4780

CVE-2020-4780

Description

OOTB build scripts does not set the secure attribute on session cookie which may impact IBM Curam Social Program Management 7.0.9 and 7.0,10. The purpose of the 'secure' attribute is to prevent cookies from being observed by unauthorized parties. IBM X-Force ID: 189158.

Affected products

4
  • cpe:2.3:a:ibm:curam_social_program_management:7.0.10.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:ibm:curam_social_program_management:7.0.10.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:curam_social_program_management:7.0.9.0:*:*:*:*:*:*:*
    • (no CPE)range: 7.0.9, 7.0.10
  • IBM/Curam SPMv5
    Range: 7.0.9

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.