cbcvebase.
CVE-2023-33847
published 2023-06-08

CVE-2023-33847: IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 does not set the secure attribute on authorization…

PriorityP411low3.1CVSS 3.1
AVNACHPRNUIRSUCLINAN
EPSS
0.63%
46.0th percentile
IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 257102.

Affected

8 ranges
VendorProductVersion rangeFixed in
ibmcics_tx
ibmcics_tx
ibmcics_tx_advanced
ibmcics_tx_standard
ibmtxseries_for_multiplatform
ibmtxseries_for_multiplatform>= 8.2 < 8.2.0.28.2.0.2
ibmtxseries_for_multiplatform>= 9.1 < 9.1.0.29.1.0.2
ibmtxseries_for_multiplatforms
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.