CVE-2014-0634
01.04.2014, 06:28
EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.Enginsight
Vendor | Product | Version |
---|---|---|
emc | vplex_geosynchrony | 4.0 |
emc | vplex_geosynchrony | 5.0 |
emc | vplex_geosynchrony | 5.1 |
emc | vplex_geosynchrony | 5.2 |
emc | vplex_geosynchrony | 5.2.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration