PT-2023-8828 · Ibm · Ibm Txseries For Multiplatforms+2
Published
2023-06-07
·
Updated
2023-06-15
·
CVE-2023-33849
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM TXSeries for Multiplatforms versions 8.1 through 9.1
CICS TX Standard version 11.1
CICS TX Advanced versions 10.1 through 11.1
Description
The issue is related to the transmission of sensitive information in query parameters using an unprotected communication channel, which could be intercepted using man-in-the-middle techniques. This could allow a remote attacker to gain unauthorized access to confidential information.
Recommendations
For IBM TXSeries for Multiplatforms versions 8.1 through 9.1, consider implementing secure communication protocols to protect query parameters.
For CICS TX Standard version 11.1, restrict access to sensitive information transmitted via query parameters until a secure communication method is implemented.
For CICS TX Advanced versions 10.1 through 11.1, disable the use of query parameters for transmitting sensitive information until a patch or secure alternative is available.
Fix
Cleartext Transmission of Sensitive Information
Missing Encryption of Sensitive Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cics Tx Advanced
Cics Tx Standard
Ibm Txseries For Multiplatforms