Ibm Cics Tx vulnerabilities
46 known vulnerabilities affecting ibm/cics_tx.
Total CVEs
46
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH13MEDIUM27LOW5
Vulnerabilities
Page 3 of 3
CVE-2022-34163MEDIUMCVSS 6.1v11.12022-08-01
CVE-2022-34163 [MEDIUM] CWE-79 CVE-2022-34163: IBM CICS TX 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by t
IBM CICS TX 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 229333.
nvd
CVE-2022-34306MEDIUMCVSS 5.4v11.12022-07-08
CVE-2022-34306 [MEDIUM] CWE-79 CVE-2022-34306: IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTTP header injection, caused by improper va
IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 229435.
nvd
CVE-2022-34167MEDIUMCVSS 5.4v11.12022-07-08
CVE-2022-34167 [MEDIUM] CWE-79 CVE-2022-34167: IBM CICS TX Standard and Advanced 11.1 is vulnerable to stored cross-site scripting. This vulnerabil
IBM CICS TX Standard and Advanced 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 229432.
nvd
CVE-2022-34160MEDIUMCVSS 5.4v11.12022-07-08
CVE-2022-34160 [MEDIUM] CWE-79 CVE-2022-34160: IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTML injection. A remote attacker could inje
IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 229330.
nvd
CVE-2022-34166MEDIUMCVSS 5.4v11.12022-07-08
CVE-2022-34166 [MEDIUM] CWE-79 CVE-2022-34166: IBM CICS TX Standard and Advanced 11.1 is vulnerable to cross-site scripting. This vulnerability all
IBM CICS TX Standard and Advanced 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 229430.
nvd
CVE-2022-31767CRITICALCVSS 9.8fixed in 11.1v11.12022-06-24
CVE-2022-31767 [CRITICAL] CWE-78 CVE-2022-31767: IBM CICS TX Standard and Advanced 11.1 could allow a remote attacker to execute arbitrary commands o
IBM CICS TX Standard and Advanced 11.1 could allow a remote attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 227980.
nvd
← Previous3 / 3