IBM Security Directory Integrator and IBM Security Verify Directory Integrator Session Cookie Vulnerability

Vulnerability

A vulnerability exists in IBM Security Directory Integrator version 7.2.0 and IBM Security Verify Directory Integrator version 10.0.0, where the secure attribute is not applied to authorization tokens or session cookies. This oversight allows attackers to intercept cookie values by sending a link to a user or embedding it in a site the user visits. The cookie would then be transmitted to the insecure link, enabling the attacker to snoop on the traffic and capture the cookie value.

Impact

Exploitation of this vulnerability could lead to the interception of session cookies, allowing attackers to hijack user sessions or access sensitive information contained in the cookies.

Remediation

Users are advised to update to IBM Security Directory Integrator version 7.2.0-ISS-SDI-FP0013 or IBM Security Verify Directory Integrator version 10.0.0.2. Instructions for downloading these updates are available on the IBM Support Fix Central website.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
1.7
exploitability
5.6
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.