Search

Contact Us

Log in

Vulnerabilities / SSL cookie without Secure flag

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

Severity
low
CWE NameSSL cookie without Secure flag
CWE IDCWE-614
CWE Score3.1
Compliance
OWASP TOP10 -> A2, A7
PCI-DSS -> 6.5.10
HIPAA -> 164.306(a)
CVSS3.0
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredNone
User InteractionRequired
ScopeUnchanged
Confidentiality ImpactLow
Integrity ImpactNone
Availability ImpactNone
SSL cookie without Secure flag