Lucene search

K
ibmIBMA557C1967A3DAAE1F6D729C9CDB1B9630B167EF631099EB792F1519E96BE1E79
HistoryNov 03, 2023 - 5:54 p.m.

Security Bulletin: "Weak or Unsupported ciphers" vulnerability may affect IBM CICS TX Advanced 10.1

2023-11-0317:54:07
www.ibm.com
24
ibm cics tx advanced
weak ciphers
unsupported ciphers
vulnerability
cryptographic algorithms
ibm
fix
linux

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

31.8%

Summary

“Weak or Unsupported ciphers” vulnerability may affect IBM CICS TX Advanced 10.1. IBM CICS TX Advanced has addressed the applicable vulnerability.

Vulnerability Details

CVEID:CVE-2023-38361
**DESCRIPTION:**IBM CICS TX Advanced uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
CVSS Base score: 5.9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/260770 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM CICS TX Advanced 10.1

Remediation/Fixes

Product Version Platform Remediation / Fix
IBM CICS TX Advanced

10.1

| Linux| Fix Central link

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmcics_txMatch10.1
VendorProductVersionCPE
ibmcics_tx10.1cpe:2.3:a:ibm:cics_tx:10.1:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

31.8%

Related for A557C1967A3DAAE1F6D729C9CDB1B9630B167EF631099EB792F1519E96BE1E79