CVE-2022-34312: IBM CICS TX information disclosure
Published Oct 31, 2022
·Updated
IBM CICS TX 11.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 229447.
Other sources
IBM CICS TX allows web pages to be stored locally which can be read by another user on the system.
— IBM
Affected Software
3 affected components
IBM CICS TX Standard<=All
IBM CICS TX=11.1
IBM CICS TX=11.1
Remediation
Patch Available
Patch Available
Event History
Oct 31, 2022
CVE Published
12:00 AM
Nov 14, 2022
CVE Published
via MITRE·05:49 PM
Data Sourced
via MITRE·05:49 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-34312.
2
What is the severity level of CVE-2022-34312?
CVE-2022-34312 has a severity level of medium.
3
How does CVE-2022-34312 affect IBM CICS TX?
CVE-2022-34312 allows web pages to be stored locally in IBM CICS TX 11.1, which can be read by another user on the system.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-34312?
The CWE ID for CVE-2022-34312 is CWE-922 and CWE-200.
5
How can I fix CVE-2022-34312?
To fix CVE-2022-34312, upgrade to IBM CICS TX Advanced version 11.1.0.0-iFix5 or later.