IBM PowerHA SystemMirror for i Session Cookie Vulnerability

Vulnerability

A vulnerability exists in IBM PowerHA SystemMirror for i versions 7.4 and 7.5, where the secure attribute is not applied to authorization tokens or session cookies. This oversight allows attackers to intercept cookie values by sending a non-secure link to a user or embedding it in a site the user visits. The cookies would then be transmitted over the insecure link, enabling the attacker to snoop on the traffic and capture the cookie values.

Impact

Exploitation of this vulnerability could lead to the interception of session cookies, potentially allowing for session hijacking.

Remediation

Users can apply a Program Temporary Fix (PTF) to address this vulnerability. For IBM i release 7.5, the PTF number is SJ03222, and for release 7.4, it is SJ03274.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
1.5
exploitability
5.6
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.