IBM Cloud Pak System does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7254419 |
Configurations
No configuration.
History
04 Feb 2026, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-04 21:15
Updated : 2026-02-05 14:57
NVD link : CVE-2023-38281
Mitre link : CVE-2023-38281
CVE.ORG link : CVE-2023-38281
JSON object : View
Products Affected
No product.
CWE
CWE-209
Generation of Error Message Containing Sensitive Information
