First published: Mon Oct 31 2022(Updated: )
IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. X-Force ID: 229449.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM CICS TX | =11.1 | |
IBM CICS TX | =11.1 | |
IBM CICS TX Advanced | <=11.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-34313 is medium with a CVSS score of 4.3.
CVE-2022-34313 affects IBM CICS TX 11.1 by not setting the secure attribute on authorization tokens or session cookies.
Attackers can exploit CVE-2022-34313 by sending a http:// link to a user or by planting this link in a site the user goes to, allowing them to obtain the cookie values.
Yes, a patch is available for CVE-2022-34313. You can find the patch at [insert link].
The Common Weakness Enumeration (CWE) number for CVE-2022-34313 is 200.