CVE-2023-38362: IBM CICS TX information disclosure
Published Mar 4, 2024
·Updated
IBM CICS TX Advanced 10.1 could disclose sensitive information to a remote attacker due to observable discrepancy in HTTP responses. IBM X-Force ID: 260814.
Affected Software
1 affected component
IBM CICS TX=10.1
Event History
Mar 4, 2024
CVE Published
via MITRE·03:56 PM
Data Sourced
via MITRE·03:56 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-38362?
CVE-2023-38362 has been classified as a moderate severity vulnerability due to its potential to expose sensitive information.
2
How do I fix CVE-2023-38362?
To mitigate CVE-2023-38362, update IBM CICS TX Advanced to the latest version that addresses this vulnerability.
3
What type of attack does CVE-2023-38362 allow?
CVE-2023-38362 allows remote attackers to potentially disclose sensitive information through observable discrepancies in HTTP responses.
4
Which versions of IBM CICS TX is affected by CVE-2023-38362?
CVE-2023-38362 specifically affects IBM CICS TX Advanced version 10.1.
5
Is there a workaround for CVE-2023-38362?
There are currently no known workarounds for CVE-2023-38362 except for applying the necessary software updates.