PT-2024-29547 · Ibm · Ibm Txseries For Multiplatforms

Published

2024-11-01

·

Updated

2024-11-15

·

CVE-2024-41738

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM TXSeries for Multiplatforms version 10.1
Description The issue allows an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request, which could be obtained using man-in-the-middle techniques. This could potentially expose sensitive information.
Recommendations For IBM TXSeries for Multiplatforms version 10.1, consider disabling the use of HTTP GET methods to process sensitive requests until a patch is available. Restrict access to sensitive information and minimize the use of query strings in HTTP requests to reduce the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-41738

Affected Products

Ibm Txseries For Multiplatforms