MEDIUM🇵🇱 Wersja polska

CVE-2022-38386

CVSS 5.9v3.1pub. 2024-05-01upd. 2025-08-13

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10.12.0 through 1.10.19.0 does not set the SameSite attribute for sensitive cookies which could allow an attacker to obtain sensitive information using man-in-the-middle techniques. IBM X-Force ID: 233778.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
  • IBM Cloud Pak For Security

    APP
    Ibm
    1.10.0.0 – 1.10.11.0
  • IBM Qradar Suite

    APP
    Ibm
    1.10.12.0 – 1.10.19.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-25022CRITICAL9.6PL ✓same product

IBM QRadar Suite / Cloud Pak for Security: ujawnienie danych w plikach konfiguracyjnych

CVE-2021-20578CRITICAL9.8PL ✓same product

IBM Cloud Pak for Security — pominięcie uwierzytelniania (Auth Bypass)

CVE-2021-20538CRITICAL9.1PL ✓same product

Nieprawidłowa autoryzacja w IBM Cloud Pak for Security

CVE-2020-4627CRITICAL9.0PL ✓same product

CSV Injection w IBM Cloud Pak for Security umożliwia zdalne wykonanie kodu

CVE-2025-25021HIGH7.2same product

IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0...