CVE-2022-34309: IBM CICS TX information disclosure
IBM CICS TX Standard and Advanced 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 229440.
Other sources
IBM CICS TX uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-34309?
CVE-2022-34309 is classified as a medium-severity vulnerability due to the use of weaker cryptographic algorithms.
How do I fix CVE-2022-34309?
To address CVE-2022-34309, update IBM CICS TX Standard or Advanced to the latest version that enhances cryptographic security.
Which IBM products are affected by CVE-2022-34309?
CVE-2022-34309 affects IBM CICS TX Standard and Advanced version 11.1 and all prior versions.
What type of information can be compromised due to CVE-2022-34309?
CVE-2022-34309 could potentially allow attackers to decrypt highly sensitive information processed by affected IBM CICS TX systems.
Is CVE-2022-34309 dependent on specific configurations?
CVE-2022-34309 is not dependent on specific configurations but rather arises from the inherent use of weaker cryptographic algorithms.