IBM Jazz for Service Management 1.1.3.0 through 1.1.3.25 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7249820 |
|
History
Wed, 05 Nov 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ibm:jazz_for_service_management:*:*:*:*:*:*:*:* |
Fri, 31 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Oct 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Jazz for Service Management 1.1.3.0 through 1.1.3.25 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. | |
| Title | IBM Jazz for Service Management is vulnerable to "filter" cookie not sent over SSL | |
| First Time appeared |
Ibm
Ibm jazz For Service Management |
|
| Weaknesses | CWE-614 | |
| CPEs | cpe:2.3:a:ibm:jazz_for_service_management:1.1.3.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:jazz_for_service_management:1.1.3.25:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm jazz For Service Management |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2025-10-31T13:05:32.799Z
Updated: 2025-10-31T13:43:40.821Z
Reserved: 2025-04-15T21:16:43.936Z
Link: CVE-2025-36249
Updated: 2025-10-31T13:43:32.783Z
Status : Analyzed
Published: 2025-10-31T13:15:33.823
Modified: 2025-11-05T19:47:32.237
Link: CVE-2025-36249
No data.