Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Simon_s
Explorer

Cookie Does Not Contain The "HTTPOnly" Attribute port 4434/tcp

A few days ago we did a vulnerability test on the Gateway and it was reported that the cookie does not contain the "HTTPOnly" attribute.
This can cause the following:
"Cookies without the "HTTPOnly" attribute are allowed to be accessed via JavaScript. Cross-site scripting attacks can steal cookies, which could result in user impersonation or compromise the application account."

Any recommendations on how to fix this vulnerability???

 

Also a second vulnerability related to the previous one:
Cookie Does Not Contain The "secure" Attribute port 4434/tcp

The impact:
Cookies with the "secure" attribute can only be sent over HTTPS. Cookies sent over HTTP expose an unsuspecting user to tracking attacks that could result in user impersonation or compromise the application account.

Any suggestions?

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

For this to be exploitable, we would have to allow the appliance to be manageable over HTTP.
There is no supported configuration to enable this.
Therefore, this vulnerability is not really applicable.

If you need to add these headers for compliance reasons, see: https://support.checkpoint.com/results/sk/sk158252
Don't believe this applies to Quantum Spark appliances.
In which case, I would consult with the TAC.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events