Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:NHcltech Bigfix Webui
APPHcltechall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2023-28019MEDIUM5.5same product
Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue ...
CVE-2023-28020MEDIUM4.7same product
URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an ...
CVE-2023-28021MEDIUM5.9same product
The BigFix WebUI uses weak cipher suites.
CVE-2023-28023MEDIUM4.9same product
A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44...
CVE-2022-38655MEDIUM6.4same product
BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevan...