CVE-2025-1330: IBM CICS TX code execution
IBM CICS TX and IBM TXSeries for Multiplatforms could allow a local user to execute arbitrary code on the system due to failure to handle DNS return requests by the gethostbyname function.
Other sources
IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on the system due to failure to handle DNS return requests by the gethostbyname function.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1330?
CVE-2025-1330 has a high severity rating due to its ability to allow local users to execute arbitrary code.
How do I fix CVE-2025-1330?
To fix CVE-2025-1330, apply the latest patches provided by IBM for affected versions of CICS TX Standard and Advanced.
Which versions of IBM CICS TX are affected by CVE-2025-1330?
CVE-2025-1330 affects IBM CICS TX Standard versions up to 11.1 and IBM CICS TX Advanced versions 10.1 and 11.1.
What type of vulnerability is CVE-2025-1330?
CVE-2025-1330 is a local code execution vulnerability caused by improper handling of DNS return requests.
Who is responsible for addressing CVE-2025-1330?
IBM is responsible for addressing CVE-2025-1330 by providing updates and patches for affected software.