Lucene search

K
ibmIBM86F25FFE9574ED5ACCAEBE1A4E550CDB9BE0D26F0FB2A3B00FC14A5B593D8C64
HistoryFeb 14, 2023 - 9:14 p.m.

Security Bulletin: IBM CICS TX Standard is vulnerable to allowing attackers access to an application via insecure session cookies (CVE-2022-34313).

2023-02-1421:14:53
www.ibm.com
26
ibm cics tx standard
insecure session cookies
attackers access
cve-2022-34313
vulnerability
fix
ibm
application

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

35.3%

Summary

IBM CICS TX Standard could allow attackers to access an application via insecure session cookies. The fix removes this vulnerability (CVE-2022-34313) from IBM CICS TX Standard.

Vulnerability Details

CVEID:CVE-2022-34313
**DESCRIPTION:**IBM CICS TX does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic
CVSS Base score: 4.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/229449 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM CICS TX Standard All

Remediation/Fixes

Product |

Version

|

Defect

|

Remediation / First Fix

—|—|—|—

IBM CICS TX Standard

|

11.1

|

127642

| Download fix here

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmcics_txMatchanystandard
VendorProductVersionCPE
ibmcics_txanycpe:2.3:a:ibm:cics_tx:any:*:*:*:standard:*:*:*

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

35.3%

Related for 86F25FFE9574ED5ACCAEBE1A4E550CDB9BE0D26F0FB2A3B00FC14A5B593D8C64