CVE-2021-40650: Medium severity Softwareag Connx vulnerability
In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Ensure that cookies issued by the application in Connx Version 6.2.0.1269 (20210623) are configured with the secure flag set.
Connx Secure flag on cookies = Set to enabled (true) for issued cookies
Event History
Frequently Asked Questions
What is CVE-2021-40650?
CVE-2021-40650 is a vulnerability in Connx Version 6.2.0.1269 (20210623) where a cookie can be issued by the application without the secure flag set.
What is the severity level of CVE-2021-40650?
CVE-2021-40650 has a severity level of medium, with a CVSS score of 6.5.
How does CVE-2021-40650 affect Connx Version 6.2.0.1269?
CVE-2021-40650 affects Connx Version 6.2.0.1269 by allowing a cookie to be issued without the secure flag set.
How can I fix the CVE-2021-40650 vulnerability?
To fix the CVE-2021-40650 vulnerability, ensure that the secure flag is set for all cookies issued by the Connx application.
Where can I find more information about CVE-2021-40650?
More information about CVE-2021-40650 can be found on the Connx website or the GitHub repository associated with the vulnerability.