First published: Thu May 08 2025(Updated: )
IBM CICS TX and IBM TXSeries for Multiplatforms could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the gets function.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM CICS Transaction Server for z/OS | <=11.1 |
IBM strongly recommends addressing the vulnerabilities now by downloading and applying the below fix. IBM CICS TX Standard 11.1 Linux Download and apply the fix from Fix Central.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1331 has a high severity rating due to its potential to allow local users to execute arbitrary code.
To fix CVE-2025-1331, you should apply the latest patches provided by IBM for affected versions of CICS TX.
CVE-2025-1331 affects IBM CICS TX Standard version 11.1 and IBM CICS TX Advanced versions 10.1 and 11.1.
Local users of IBM CICS TX and IBM TXSeries for Multiplatforms are vulnerable to CVE-2025-1331.
CVE-2025-1331 exploits the unsafe use of the gets function, which can lead to arbitrary code execution.