IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2016-0372 - Vulnerability Database

IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2016-0372

Low
Reference: CVE-2016-0372
Title: IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Overview:

IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8 4.0 before 4.0.7 iFix11 5.0 before 5.0.2 iFix18 and 6.0 before 6.0.2 iFix5 Rational Quality Manager 3.0.1.6 before iFix8 4.0 before 4.0.7 iFix11 5.0 before 5.0.2 iFix18 and 6.0 before 6.0.2 iFix5 Rational Team Concert 3.0.1.6 before iFix8 4.0 before 4.0.7 iFix11 5.0 before 5.0.2 iFix18 and 6.0 before 6.0.2 iFix5 Rational DOORS Next Generation 4.0 before 4.0.7 iFix11 5.0 before 5.0.2 iFix18 and 6.0 before 6.0.2 iFix5 Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11 5.0 before 5.0.2 iFix18 and 6.0 before 6.0.2 iFix5 Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11 5.0 before 5.0.2 iFix18 and 6.0 before 6.0.2 iFix5 and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11 5.0 before 5.0.2 iFix18 and 6.0 before 6.0.2 iFix5 do not set the secure flag for the session cookie in an https session which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.