CVE-2022-38386

EUVD-2022-40972
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10.12.0 through 1.10.19.0 does not set the SameSite attribute for sensitive cookies which could allow an attacker to obtain sensitive information using man-in-the-middle techniques.  IBM X-Force ID:  233778.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
ibmCNA
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
Affected Products (NVD)
VendorProductVersion
ibmcloud_pak_for_security
1.10.11.0 ≤
𝑥
≤ 1.10.11.0
ibmqradar_suite
1.10.19.0 ≤
𝑥
≤ 1.10.19.0
ibmcloud_pak_for_security
1.10.0.0 ≤
𝑥
≤ 1.10.11.0
ibmqradar_suite
1.10.12.0 ≤
𝑥
≤ 1.10.19.0
𝑥
= Vulnerable software versions