CVE-2022-34160: XSS
IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 229330.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-34160.
What is the severity rating of CVE-2022-34160?
The severity rating of CVE-2022-34160 is medium with a value of 5.4.
Which versions of IBM CICS TX are affected by CVE-2022-34160?
IBM CICS TX Standard and Advanced 11.1 are affected by CVE-2022-34160.
How can a remote attacker exploit this vulnerability?
A remote attacker can exploit this vulnerability by injecting malicious HTML code that will be executed in the victim's web browser within the security context of the hosting site.
Is there a solution or patch available for CVE-2022-34160?
Yes, IBM has released patches and workarounds to address CVE-2022-34160. Please refer to the IBM support pages for more information.