CVE-2021-40649: Medium severity software ag connx vulnerability
Published Jun 14, 2022
·Updated
In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.
Affected Software
1 affected component
Softwareag Connx=6.2.0.1269
Event History
Jun 14, 2022
CVE Published
via MITRE·09:35 AM
Data Sourced
via MITRE·09:35 AM
Description
Frequently Asked Questions
1
What is CVE-2021-40649?
CVE-2021-40649 is a vulnerability in Connx Version 6.2.0.1269 (20210623) where a cookie can be issued by the application without the HttpOnly flag set.
2
How severe is CVE-2021-40649?
CVE-2021-40649 has a severity rating of 6.5 (Medium).
3
What software is affected by CVE-2021-40649?
Connx Version 6.2.0.1269 (20210623) is affected by CVE-2021-40649.
4
How can I fix CVE-2021-40649?
To fix CVE-2021-40649, update Connx to a version where the HttpOnly flag is properly set for cookies.
5
Where can I find more information about CVE-2021-40649?
You can find more information about CVE-2021-40649 on the Connx website and the GitHub repository for CVE-2021-40649.