CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.3. It may be remotely exploitable.
CVE
CVE-2016-6344
Severity
MEDIUM
CVSS
5.3
EPSS
2.19%
Original NVD Description
Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes it easier for remote attackers to obtain potentially sensitive information via script access to the cookies.