VDB
RHSA-2018%3A2840
RHSA-2018%3A2840
PUBLISHED
It was found that Hawtio console does not set HTTPOnly or Secure attributes on cookies. An attacker could use this flaw to rerieve an authenticated user's SessionID, and possibly conduct further attacks with the permissions of the authenticated user.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Fuse 6.3 | |
| Red Hat | Red Hat JBoss A-MQ 6.3 |
Timeline
- Oct 1, 2018 CVE Published
- Jan 28, 2026 CVE Updated
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2018:2840 advisory
- https://access.redhat.com/security/updates/classification/#low advisory
- https://access.redhat.com/documentation/en-us/red_hat_fuse/6.3/ advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=jboss.fuse&downloadType=securityPatches&version=6.3 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1249182 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2018/rhsa-2018_2840.json advisory
- https://access.redhat.com/security/cve/CVE-2015-5183 advisory
- https://www.cve.org/CVERecord?id=CVE-2015-5183 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2015-5183 advisory