Vulnerabilities (CVE)

Filtered by CWE-1275
Total 25 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-43173 1 Ibm 1 Concert 2026-06-17 N/A 3.7 LOW
IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.
CVE-2024-42212 1 Hcltech 1 Bigfix Compliance 2026-06-17 N/A 5.4 MEDIUM
HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user's browser into making unintended requests using authenticated sessions.
CVE-2024-30155 1 Hcltech 1 Hcl Sx 2026-06-17 N/A 5.5 MEDIUM
HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).
CVE-2023-53957 1 Kimai 1 Kimai 2026-06-17 N/A 9.8 CRITICAL
Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.
CVE-2022-38386 1 Ibm 2 Cloud Pak For Security, Qradar Suite 2026-06-17 N/A 5.9 MEDIUM
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10.12.0 through 1.10.19.0 does not set the SameSite attribute for sensitive cookies which could allow an attacker to obtain sensitive information using man-in-the-middle techniques. IBM X-Force ID: 233778.