cbcvebase.

Ibm Cics Tx vulnerabilities

46 known vulnerabilities affecting ibm/cics_tx.

Total CVEs
46
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH13MEDIUM27LOW5

Vulnerabilities

Page 3 of 3
CVE-2022-34311P4MEDIUMCVSS 4.3v11.12024-02-12
CVE-2022-34311 [MEDIUM] CWE-522 CVE-2022-34311: IBM CICS TX Standard and Advanced 11.1 could allow a user with physical access to the web browser to IBM CICS TX Standard and Advanced 11.1 could allow a user with physical access to the web browser to gain access to the user's session due to insufficiently protected credentials. IBM X-Force ID: 229446.
nvd
CVE-2023-33849P4LOWCVSS 3.7v10.1v11.12023-06-07
CVE-2023-33849 [LOW] CWE-311 CVE-2023-33849: IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11 IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could transmit sensitive information in query parameters that could be intercepted using man in the middle techniques. IBM X-Force ID: 257105.
nvd
CVE-2023-33847P4LOWCVSS 3.1v10.1v11.12023-06-08
CVE-2023-33847 [LOW] CVE-2023-33847: IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 1 IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link a
nvd
CVE-2022-34313P4LOWCVSS 3.1v11.12022-11-14
CVE-2022-34313 [LOW] CWE-200 CVE-2022-34313: IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Atta IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. X-Fo
nvd
CVE-2022-34312P4LOWCVSS 3.3v11.12022-11-14
CVE-2022-34312 [LOW] CWE-200 CVE-2022-34312: IBM CICS TX 11.1 allows web pages to be stored locally which can be read by another user on the sys IBM CICS TX 11.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 229447.
nvd
CVE-2022-34314P4LOWCVSS 3.3v11.12022-11-14
CVE-2022-34314 [LOW] CWE-200 CVE-2022-34314: IBM CICS TX 11.1 could disclose sensitive information to a local user due to insecure permission se IBM CICS TX 11.1 could disclose sensitive information to a local user due to insecure permission settings. IBM X-Force ID: 229450.
nvd