CWE-614: CWE-614

12
Total CVEs
1
Critical
2
High
5.8
Avg CVSS

Yearly Trend

2025
8
2024
3
2022
1

Top Affected Vendors

1 Ibm 6
2 Hcltech 2
3 Kentico 1
4 Mozilla 1
5 Endress 1

All CWE-614 CVEs (12)

CVE-2025-8037
9.1

This vulnerability allows an attacker to set a nameless cookie with an equals sign in its value, which can shadow other cookies including those with t...

Jul 22, 2025
CVE-2024-2493
7.5

CVE-2024-2493 is a session hijacking vulnerability in Hitachi Ops Center Analyzer that allows attackers to steal or manipulate user sessions. This aff...

Apr 23, 2024
CVE-2021-27764
7.4

CVE-2021-27764 is a security misconfiguration vulnerability in HCL Domino WebUI where cookies are set without HTTPOnly flags. This allows attackers to...

May 6, 2022
CVE-2025-52632
6.5

A missing Secure attribute in SSL cookies in HCL AION allows attackers to intercept session cookies over unencrypted HTTP connections. This affects HC...

Oct 10, 2025
CVE-2025-27450
6.5

This vulnerability in the MEAC300-FNADE4 device allows session hijacking because cookies lack the Secure attribute. Attackers can intercept PHPSESSID ...

Jul 3, 2025
CVE-2024-58317
5.3

A cookie security configuration vulnerability in Kentico Xperience allows attackers to bypass SSL requirements when setting administration cookies via...

Dec 18, 2025
CVE-2023-33860
5.3

IBM Security QRadar EDR 3.12 fails to set the 'secure' attribute on authorization tokens and session cookies, allowing attackers to potentially steal ...

Jul 10, 2024
CVE-2024-28770
4.8

This vulnerability allows attackers to steal session cookies or authorization tokens from IBM Security Directory Integrator users by intercepting unen...

Jan 27, 2025
CVE-2025-36011
4.3

IBM Jazz for Service Management versions 1.1.3.0 through 1.1.3.24 fail to set the secure attribute on authorization tokens and session cookies, allowi...

Sep 9, 2025
CVE-2025-36026
4.3

IBM Datacap versions 9.1.7-9.1.9 fail to set the Secure attribute on authorization tokens and session cookies, allowing attackers to intercept these c...

Jun 28, 2025
CVE-2024-55897
4.3

IBM PowerHA SystemMirror for i fails to set the secure attribute on authorization tokens and session cookies, allowing attackers to steal these cookie...

Jan 3, 2025
CVE-2024-43180
4.3

IBM Concert 1.0 fails to set the secure attribute on authorization tokens and session cookies, allowing attackers to intercept these cookies when user...

Sep 13, 2024

About CWE-614 (CWE-614)

Our database tracks 12 CVEs classified as CWE-614, with 1 rated critical and 2 rated high severity. The average CVSS score for CWE-614 vulnerabilities is 5.8.

External reference: View CWE-614 on MITRE CWE →

Monitor CWE-614 Vulnerabilities

Get alerted when new CWE-614 CVEs affect your infrastructure.

Start Monitoring Free