Information disclosure in Red Hat Process Automation Manager (formerly JBoss BPM Suite) - CVE-2016-6344

 

Information disclosure in Red Hat Process Automation Manager (formerly JBoss BPM Suite) - CVE-2016-6344

Published: September 7, 2016 / Updated: August 9, 2020


Vulnerability identifier: #VU40132
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6344
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes it easier for remote attackers to obtain potentially sensitive information via script access to the cookies.


Affected software

Red Hat Process Automation Manager (formerly JBoss BPM Suite)

How to mitigate CVE-2016-6344

Install update from vendor's website.


External References

Related Security Bulletins