IBM Jazz for Service Management Sensitive Cookie Vulnerability Allowing Cookie Theft

Vulnerability

A vulnerability exists in IBM Jazz for Service Management versions 1.1.3.0 through 1.1.3.24, where the secure attribute is not applied to authorization tokens or session cookies. This oversight allows attackers to intercept cookie values by sending a non-secure link to a user or embedding it in a site the user visits. The cookies would then be transmitted over the insecure link, enabling the attacker to snoop on the traffic and capture the cookie values.

Impact

Exploitation of this vulnerability could lead to unauthorized access to user sessions or sensitive information contained in the cookies.

Remediation

Users can upgrade to IBM Jazz for Service Management version 1.1.3.25 to address this vulnerability.

Added: Sep 9, 2025, 8:39 PM
Updated: Sep 9, 2025, 8:39 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
1.7
exploitability
5.6
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.