4.3

CVE-2022-34311

IBM CICS TX session fixation

IBM CICS TX Standard and Advanced 11.1 could allow a user with physical access to the web browser to gain access to the user's session due to insufficiently protected credentials.  IBM X-Force ID:  229446.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Cics Tx Version 11.1 SwEdition advanced
Ibm ≫ Cics Tx Version 11.1 SwEdition standard
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.275
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 0.9 3.4
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
IBM 4.3 0.9 3.4
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

https://exchange.xforce.ibmcloud.com/vulnerabilities/229446
VDB Entry
https://www.ibm.com/support/pages/node/6832928
Vendor Advisory
https://www.ibm.com/support/pages/node/6832930
Vendor Advisory