VYPR

CWE-614

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

VariantDraft

Description

The Secure attribute for sensitive cookies in HTTPS sessions is not set.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-102

CVEs mapped to this weakness (67)

page 2 of 4
  • CVE-2020-27651MedOct 29, 2020
    risk 0.38cvss 5.8epss 0.01

    Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.

  • CVE-2020-27650MedOct 29, 2020
    risk 0.38cvss 5.8epss 0.01

    Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.

  • CVE-2026-22617MedApr 16, 2026
    risk 0.37cvss 5.7epss 0.00

    Eaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow a network‑based attacker to intercept the cookie and exploit it through a man‑in‑the‑middle attack. This security issue has been fixed in the latest version of Eaton IPP…

  • CVE-2024-35211MedJun 11, 2024
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server, after a successful login, sets the session cookie on the browser, without applying any security attributes (such as “Secure”, “HttpOnly”, or…

  • CVE-2022-4683MedDec 23, 2022
    risk 0.35cvss 6.5epss 0.00

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository usememos/memos prior to 0.9.0.

  • CVE-2024-58317MedDec 18, 2025
    risk 0.34cvss 5.3epss 0.00

    A cookie security configuration vulnerability in Kentico Xperience allows attackers to bypass SSL requirements when setting administration cookies via web.config. The vulnerability affects .NET Framework projects by incorrectly handling the 'requireSSL' attribute, potentially…

  • CVE-2024-41684MedJul 26, 2024
    risk 0.34cvss 5.3epss 0.00

    This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing secure flag for the session cookies associated with the router's web management interface. An attacker with remote access could exploit this by intercepting transmission within an HTTP session on the…

  • CVE-2023-33860MedJul 10, 2024
    risk 0.34cvss 5.3epss 0.00

    IBM Security QRadar EDR 3.12 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the…

  • CVE-2020-29024MedFeb 16, 2021
    risk 0.34cvss 5.3epss 0.01

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in (GTA) GoToAppliance of Secomea GateManager could allow an attacker to gain access to sensitive cookies. This issue affects: Secomea GateManager all versions prior to 9.3.

  • CVE-2026-41017MedJun 1, 2026
    risk 0.31cvss 5.9epss 0.00

    Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Airflow API server behind an HTTPS-terminating reverse proxy (e.g. nginx / Envoy / a managed load balancer that terminates TLS and forwards plaintext to the API…

  • CVE-2024-28771MedJan 27, 2025
    risk 0.31cvss 4.8epss 0.00

    IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link…

  • CVE-2024-28770MedJan 27, 2025
    risk 0.31cvss 4.8epss 0.00

    IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link…

  • CVE-2023-5866MedOct 31, 2023
    risk 0.30cvss 5.7epss 0.00

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.2.1.

  • CVE-2026-15656MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be…

  • CVE-2026-46550MedJun 23, 2026
    risk 0.28cvss 5.4epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the refresh-token cookie was set with httpOnly: true but missing both the secure flag and the sameSite attribute. Over plain HTTP the cookie could be intercepted on the network; without sameSite,…

  • CVE-2026-4820MedApr 1, 2026
    risk 0.28cvss 4.3epss 0.00

    IBM Maximo Application Suite 9.1, 9.0, 8.11, and 8.10 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie…

  • CVE-2025-36011MedSep 9, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Jazz for Service Management 1.1.3.0 through 1.1.3.24 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The…

  • CVE-2025-36026MedJun 28, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Datacap 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to…

  • CVE-2024-55897MedJan 3, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM PowerHA SystemMirror for i 7.4 and 7.5 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be…

  • CVE-2024-43180MedSep 13, 2024
    risk 0.28cvss 4.3epss 0.00

    IBM Concert 1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and…