CVE-2022-31767: OS Command Injection
IBM CICS TX could allow a remote attacker to execute arbitrary commands on the system by sending a specially crafted request.
Other sources
IBM CICS TX Standard and Advanced 11.1 could allow a remote attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 227980.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-31767?
CVE-2022-31767 is a vulnerability in IBM CICS TX Standard and Advanced 11.1 that allows a remote attacker to execute arbitrary commands on the system.
How can an attacker exploit CVE-2022-31767?
An attacker can exploit CVE-2022-31767 by sending a specially crafted request to the system.
What is the severity of CVE-2022-31767?
CVE-2022-31767 has a severity rating of 9.8 (Critical).
Which versions of IBM CICS TX are affected by CVE-2022-31767?
IBM CICS TX Standard version up to and including 11.1, and IBM CICS TX Advanced version 11.1 are affected by CVE-2022-31767.
How can I fix CVE-2022-31767?
You can fix CVE-2022-31767 by applying the patch provided by IBM for CICS TX Advanced version 11.1.