
CVE-2023-38281 IBM Cloud Pak System does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http://… https://www.cve.org/CVERecord?id=CVE-2023-38281
Post summary
The IBM Cloud Pak System fails to set the secure flag on authorization tokens or session cookies, potentially allowing attackers to read cookie values.
