First published: Tue Oct 01 2024(Updated: )
IBM CICS TX Advanced 10.1, 11.1, and Standard 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM CICS Transaction Server for z/OS | <=10.1 | |
IBM CICS Transaction Server for z/OS | <=11.1 | |
IBM CICS Transaction Server for z/OS | <=11.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-41746 is considered a medium severity vulnerability due to its potential for stored cross-site scripting attacks.
To fix CVE-2024-41746, apply the latest patches provided by IBM for CICS TX Advanced versions 10.1 and 11.1.
CVE-2024-41746 affects IBM CICS TX Advanced versions 10.1 and 11.1, as well as CICS TX Standard version 11.1.
Yes, CVE-2024-41746 can allow an attacker to execute arbitrary JavaScript code, potentially leading to credential disclosure.
Other than applying patches, users should implement web application security best practices to help mitigate risks related to CVE-2024-41746.