IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could transmit sensitive information in query parameters that could be intercepted using man in the middle techniques. IBM X-Force ID: 257105.
References
Link | Resource |
---|---|
https://www.ibm.com/support/pages/node/7001695 | Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/257105 | VDB Entry Vendor Advisory |
https://www.ibm.com/support/pages/node/7001697 | Vendor Advisory |
https://www.ibm.com/support/pages/node/7001687 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
History
15 Jun 2023, 16:56
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.7 |
CWE | CWE-311 | |
CPE | cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:* cpe:2.3:a:ibm:cics_tx:11.1:*:*:*:standard:*:*:* cpe:2.3:o:hp:hp-ux:-:*:*:*:*:*:*:* cpe:2.3:a:ibm:txseries_for_multiplatforms:8.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:txseries_for_multiplatforms:8.2:*:*:*:*:*:*:* cpe:2.3:a:ibm:cics_tx:10.1:*:*:*:advanced:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:a:ibm:cics_tx:11.1:*:*:*:advanced:*:*:* cpe:2.3:a:ibm:txseries_for_multiplatforms:9.1:*:*:*:*:*:*:* |
|
References | (MISC) https://www.ibm.com/support/pages/node/7001687 - Vendor Advisory | |
References | (MISC) https://exchange.xforce.ibmcloud.com/vulnerabilities/257105 - VDB Entry, Vendor Advisory | |
References | (MISC) https://www.ibm.com/support/pages/node/7001697 - Vendor Advisory | |
References | (MISC) https://www.ibm.com/support/pages/node/7001695 - Vendor Advisory | |
First Time |
Ibm cics Tx
Ibm txseries For Multiplatforms Linux Linux linux Kernel Hp hp-ux Ibm aix Hp Ibm |
07 Jun 2023, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-07 22:15
Updated : 2023-06-15 16:56
NVD link : CVE-2023-33849
Mitre link : CVE-2023-33849
JSON object : View
Products Affected
ibm
- txseries_for_multiplatforms
- cics_tx
- aix
hp
- hp-ux
linux
- linux_kernel
CWE
CWE-311
Missing Encryption of Sensitive Data