PT-2009-3158 · Ibm · Ibm Txseries For Multiplatforms
Published
2009-02-25
·
Updated
2017-08-08
·
CVE-2009-0505
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM TXSeries for Multiplatforms version 6.2 GA
Description
The issue is related to the CICS listener in IBM TXSeries for Multiplatforms, which may allow remote authenticated users to cause a denial of service or have other unspecified impacts. This occurs when the CICS listener waits for a forcepurge acknowledgement from the CICS Application Server after an eci response timeout, and the acknowledgement is slow or nonexistent.
Recommendations
For IBM TXSeries for Multiplatforms version 6.2 GA, consider implementing measures to handle forcepurge acknowledgements more efficiently, such as setting timeouts or implementing retry mechanisms, to minimize the risk of denial of service. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Txseries For Multiplatforms