First published: Fri Jul 29 2022(Updated: )
IBM CICS TX 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 229333.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM CICS TX | =11.1 | |
IBM CICS TX | =11.1 | |
IBM CICS TX Standard | <=11.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34163 is a vulnerability in IBM CICS TX 11.1 that allows for HTTP header injection, leading to potential attacks such as cross-site scripting, cache poisoning, or session hijacking.
CVE-2022-34163 has a severity rating of 6.1, which is considered medium.
To fix CVE-2022-34163, apply the patch provided by IBM CICS TX Advanced version 11.1.0.0-iFix3 or upgrade to a later version.
You can find more information about CVE-2022-34163 on the IBM X-Force ID page (229333) or the IBM Support page.
The CWE of CVE-2022-34163 is 79, which refers to improper neutralization of input during web page generation.