Lucene search

K
ibmIBM6E16491755CD1CF75E6808210C1F51F621E91B3D7815E56F623F1E13A830722D
HistoryNov 03, 2023 - 5:51 p.m.

Security Bulletin: "Incorrect/Missing Security Headers" may affect IBM CICS TX Advanced 10.1

2023-11-0317:51:48
www.ibm.com
23
ibm cics tx advanced
cross-site scripting
cve-2023-38364
vulnerability
linux
fix
ibm support

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6.4

Confidence

High

EPSS

0

Percentile

13.1%

Summary

“Incorrect/Missing Security Headers” may affect IBM CICS TX Advanced 10.1. IBM CICS TX Advanced has addressed the applicable vulnerability.

Vulnerability Details

CVEID:CVE-2023-38364
**DESCRIPTION:**IBM CICS TX Advanced is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS Base score: 6.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/260821 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM CICS TX Advanced 10.1

Remediation/Fixes

Product Version Platform Remediation / Fix
IBM CICS TX Advanced

10.1

| Linux| Fix Central link

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmcics_txMatch10.1
VendorProductVersionCPE
ibmcics_tx10.1cpe:2.3:a:ibm:cics_tx:10.1:*:*:*:*:*:*:*

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6.4

Confidence

High

EPSS

0

Percentile

13.1%

Related for 6E16491755CD1CF75E6808210C1F51F621E91B3D7815E56F623F1E13A830722D