IBM Jazz for Service Management Cookie Vulnerability Due to Missing Secure Attribute

Vulnerability

A vulnerability exists in IBM Jazz for Service Management versions 1.1.3.0 through 1.1.3.25, where the secure attribute is not applied to authorization tokens or session cookies. This oversight allows attackers to intercept cookie values by sending an unsecured HTTP link to a user or embedding such a link on a site the user visits. The cookies would be transmitted over the insecure link, enabling the attacker to capture the cookie values by monitoring the traffic.

Impact

Exploitation of this vulnerability could lead to interception of session cookies, potentially allowing for session hijacking.

Remediation

Users can upgrade to IBM Jazz for Service Management version 1.1.3.26. Instructions for downloading this version are available on the IBM Support Fix Central website.

Added: Oct 31, 2025, 1:19 PM
Updated: Oct 31, 2025, 1:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
1.7
exploitability
5.6
remediation
7.7
relevance
0.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.