CVE-2025-1330: IBM CICS TX code execution

Published May 8, 2025
·
Updated

IBM CICS TX and IBM TXSeries for Multiplatforms could allow a local user to execute arbitrary code on the system due to failure to handle DNS return requests by the gethostbyname  function.

Other sources

IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1  could allow a local user to execute arbitrary code on the system due to failure to handle DNS return requests by the gethostbyname function.

MITRE

Affected Software

29 affected componentsFixes available
IBM CICS TX Standard
IBM CICS TX Advanced
IBM CICS TX Standard<=11.1
All of the following
Any of the following
IBM CICS TX=11.1.0.0
IBM CICS TX=11.1.0.0-interim_fix_1
IBM CICS TX=11.1.0.0-interim_fix_10
IBM CICS TX=11.1.0.0-interim_fix_11
IBM CICS TX=11.1.0.0-interim_fix_12
IBM CICS TX=11.1.0.0-interim_fix_13
IBM CICS TX=11.1.0.0-interim_fix_14
IBM CICS TX=11.1.0.0-interim_fix_15
IBM CICS TX=11.1.0.0-interim_fix_16
IBM CICS TX=11.1.0.0-interim_fix_17
IBM CICS TX=11.1.0.0-interim_fix_18
IBM CICS TX=11.1.0.0-interim_fix_19
IBM CICS TX=11.1.0.0-interim_fix_2
IBM CICS TX=11.1.0.0-interim_fix_20
IBM CICS TX=11.1.0.0-interim_fix_21
IBM CICS TX=11.1.0.0-interim_fix_22
IBM CICS TX=11.1.0.0-interim_fix_23
IBM CICS TX=11.1.0.0-interim_fix_24
IBM CICS TX=11.1.0.0-interim_fix_3
IBM CICS TX=11.1.0.0-interim_fix_4
IBM CICS TX=11.1.0.0-interim_fix_5
IBM CICS TX=11.1.0.0-interim_fix_6
IBM CICS TX=11.1.0.0-interim_fix_7
IBM CICS TX=11.1.0.0-interim_fix_8
IBM CICS TX=11.1.0.0-interim_fix_9
Linux Linux kernel

Remediation

Information

IBM strongly recommends addressing the vulnerabilities now by downloading and applying the below fix. IBM CICS TX Standard 11.1 Linux Download and apply the fix from Fix Central.

Event History

May 8, 2025
CVE Published
via IBM·12:00 AM
CVE Published
via MITRE·09:54 PM
Data Sourced
via MITRE·09:54 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-1330?

CVE-2025-1330 has a high severity rating due to its ability to allow local users to execute arbitrary code.

2

How do I fix CVE-2025-1330?

To fix CVE-2025-1330, apply the latest patches provided by IBM for affected versions of CICS TX Standard and Advanced.

3

Which versions of IBM CICS TX are affected by CVE-2025-1330?

CVE-2025-1330 affects IBM CICS TX Standard versions up to 11.1 and IBM CICS TX Advanced versions 10.1 and 11.1.

4

What type of vulnerability is CVE-2025-1330?

CVE-2025-1330 is a local code execution vulnerability caused by improper handling of DNS return requests.

5

Who is responsible for addressing CVE-2025-1330?

IBM is responsible for addressing CVE-2025-1330 by providing updates and patches for affected software.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203