First published: Fri Jul 29 2022(Updated: )
IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 229436.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM CICS TX | =11.1 | |
IBM CICS TX | =11.1 | |
IBM CICS TX Standard | <=11.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-34307 is medium with a score of 4.3.
CVE-2022-34307 affects IBM CICS TX 11.1 by not setting the secure attribute on authorization tokens or session cookies.
Attackers can exploit CVE-2022-34307 by sending a http:// link to a user or planting the link in a site the user visits to retrieve the cookie values sent to the insecure link.
The recommended fix for CVE-2022-34307 is to apply the patch provided by IBM.
You can find more information about CVE-2022-34307 on the IBM X-Force Exchange and IBM Support pages.