CVE-2024-56476
- EPSS 0.04%
- Published 02.04.2025 16:17:40
- Last modified 15.07.2025 19:16:23
IBM TXSeries for Multiplatforms 9.1 and 11.1 could allow an attacker to enumerate usernames due to an observable login attempt response discrepancy.
CVE-2025-0154
- EPSS 0.06%
- Published 02.04.2025 16:17:40
- Last modified 15.07.2025 19:22:17
IBM TXSeries for Multiplatforms 9.1 and 11.1 could disclose sensitive information to a remote attacker due to improper neutralization of HTTP headers.
CVE-2024-56474
- EPSS 0.02%
- Published 02.04.2025 16:17:39
- Last modified 16.07.2025 17:33:24
IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
CVE-2024-56475
- EPSS 0.03%
- Published 02.04.2025 16:17:39
- Last modified 15.07.2025 19:25:23
IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to crede...
CVE-2024-41742
- EPSS 0.07%
- Published 19.01.2025 15:15:20
- Last modified 16.07.2025 00:51:27
IBM TXSeries for Multiplatforms 10.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting a slowloris-type attacks, a remote attacker could exploit this vulnerability to caus...
CVE-2024-41743
- EPSS 0.07%
- Published 19.01.2025 15:15:20
- Last modified 16.07.2025 00:52:25
IBM TXSeries for Multiplatforms 10.1 could allow a remote attacker to cause a denial of service using persistent connections due to improper allocation of resources.
CVE-2024-41738
- EPSS 0.09%
- Published 01.11.2024 17:15:16
- Last modified 14.11.2024 20:51:29
IBM TXSeries for Multiplatforms 10.1 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.
CVE-2024-41741
- EPSS 0.11%
- Published 01.11.2024 17:15:16
- Last modified 14.11.2024 20:42:44
IBM TXSeries for Multiplatforms 10.1 could allow an attacker to determine valid usernames due to an observable timing discrepancy which could be used in further attacks against the system.
CVE-2023-42027
- EPSS 0.04%
- Published 03.11.2023 00:15:12
- Last modified 21.11.2024 08:22:07
IBM CICS TX Standard 11.1, Advanced 10.1, 11.1, and TXSeries for Multiplatforms 8.1, 8.2, 9.1 are vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the we...
CVE-2023-42029
- EPSS 0.06%
- Published 03.11.2023 00:15:12
- Last modified 21.11.2024 08:22:07
IBM CICS TX Standard 11.1, Advanced 10.1, 11.1, and TXSeries for Multiplatforms 8.1, 8.2, 9.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended function...