CVE-2023-33848: IBM CICS TX information disclosure
IBM CICS TX could allow a privileged user to obtain highly sensitive information by enabling debug mode.
Other sources
IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could allow a privileged user to obtain highly sensitive information by enabling debug mode. IBM X-Force ID: 257104.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM TXSeries for Multiplatforms / IBM CICS TX Standard / IBM CICS TX Advancedto a version that resolves this vulnerability.Fixed in 8.1 - Upgrade
Upgrade
IBM TXSeries for Multiplatforms / IBM CICS TX Standard / IBM CICS TX Advancedto a version that resolves this vulnerability.Fixed in 8.2 - Upgrade
Upgrade
IBM TXSeries for Multiplatforms / IBM CICS TX Standard / IBM CICS TX Advancedto a version that resolves this vulnerability.Fixed in 9.1 - Upgrade
Upgrade
IBM TXSeries for Multiplatforms / IBM CICS TX Standard / IBM CICS TX Advancedto a version that resolves this vulnerability.Fixed in CICS TX Standard - Upgrade
Upgrade
IBM TXSeries for Multiplatforms / IBM CICS TX Standard / IBM CICS TX Advancedto a version that resolves this vulnerability.Fixed in 11.1 - Upgrade
Upgrade
IBM TXSeries for Multiplatforms / IBM CICS TX Standard / IBM CICS TX Advancedto a version that resolves this vulnerability.Fixed in 10.1 - Configuration
Disable debug mode because enabling debug mode in the listed IBM CICS TX versions could allow a privileged user to obtain highly sensitive information (IBM X-Force ID: 257104).
IBM CICS TX debug mode debug mode = disable
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-33848.
What is the severity of CVE-2023-33848?
The severity of CVE-2023-33848 is medium with a CVSS score of 6.5.
How can a privileged user obtain sensitive information in IBM CICS TX?
A privileged user can obtain highly sensitive information by enabling debug mode in IBM CICS TX Standard versions 11.1.
Which versions of IBM CICS TX are affected by CVE-2023-33848?
IBM CICS TX Standard versions 11.1, CICS TX Advanced versions 10.1 and 11.1.
How can I fix CVE-2023-33848?
You can fix CVE-2023-33848 by applying the patch provided by IBM for IBM CICS TX Standard version 11.1.