Rapid7 Vulnerability & Exploit Database

F5 Networks: K15406 (CVE-2004-0462): HTTP cookie vulnerability CVE-2004-0462

Back to Search

F5 Networks: K15406 (CVE-2004-0462): HTTP cookie vulnerability CVE-2004-0462

Severity
2
CVSS
(AV:L/AC:L/Au:N/C:P/I:N/A:N)
Published
12/31/2004
Created
07/25/2018
Added
02/16/2017
Modified
10/13/2017

Description

The built-in web servers for multiple networking devices do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session with the same server.

Solution(s)

  • f5-big-ip-upgrade-latest

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;