PT-2023-8828 · Ibm · Ibm Txseries For Multiplatforms+2

Published

2023-06-07

·

Updated

2023-06-15

·

CVE-2023-33849

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM TXSeries for Multiplatforms versions 8.1 through 9.1 CICS TX Standard version 11.1 CICS TX Advanced versions 10.1 through 11.1
Description The issue is related to the transmission of sensitive information in query parameters using an unprotected communication channel, which could be intercepted using man-in-the-middle techniques. This could allow a remote attacker to gain unauthorized access to confidential information.
Recommendations For IBM TXSeries for Multiplatforms versions 8.1 through 9.1, consider implementing secure communication protocols to protect query parameters. For CICS TX Standard version 11.1, restrict access to sensitive information transmitted via query parameters until a secure communication method is implemented. For CICS TX Advanced versions 10.1 through 11.1, disable the use of query parameters for transmitting sensitive information until a patch or secure alternative is available.

Fix

Cleartext Transmission of Sensitive Information

Missing Encryption of Sensitive Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-02106
CVE-2023-33849

Affected Products

Cics Tx Advanced
Cics Tx Standard
Ibm Txseries For Multiplatforms