3.1

CVE-2023-33847

IBM CICS TX information disclosure

IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 257102.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Txseries For Multiplatform Version 8.1
   Ibm ≫ Aix Version -
   Linux ≫ Linux Kernel Version -
Ibm ≫ Txseries For Multiplatform Version >= 8.2 < 8.2.0.2
   Hp ≫ Hp-ux Version -
   Ibm ≫ Aix Version -
   Linux ≫ Linux Kernel Version -
Ibm ≫ Txseries For Multiplatform Version >= 9.1 < 9.1.0.2
   Ibm ≫ Aix Version -
   Linux ≫ Linux Kernel Version -
Ibm ≫ Cics Tx Version 10.1 SwEdition advanced
   Linux ≫ Linux Kernel Version -
Ibm ≫ Cics Tx Version 11.1 SwEdition advanced
   Linux ≫ Linux Kernel Version -
Ibm ≫ Cics Tx Version 11.1 SwEdition standard
   Linux ≫ Linux Kernel Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.63% 0.453
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.1 1.6 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
IBM 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://exchange.xforce.ibmcloud.com/vulnerabilities/257102
Vendor Advisory
VDB Entry
https://www.ibm.com/support/pages/node/7001635
Patch
Vendor Advisory
https://www.ibm.com/support/pages/node/7001641
Patch
Vendor Advisory
https://www.ibm.com/support/pages/node/7001645
Patch
Vendor Advisory