IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could transmit sensitive information in query parameters that could be intercepted using man in the middle techniques. IBM X-Force ID: 257105.
References
Link | Resource |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/257105 | VDB Entry Vendor Advisory |
https://www.ibm.com/support/pages/node/7001687 | Vendor Advisory |
https://www.ibm.com/support/pages/node/7001695 | Vendor Advisory |
https://www.ibm.com/support/pages/node/7001697 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
History
15 Jun 2023, 16:56
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:hp:hp-ux:-:*:*:*:*:*:*:* cpe:2.3:a:ibm:txseries_for_multiplatforms:9.1:*:*:*:*:*:*:* cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:* cpe:2.3:a:ibm:txseries_for_multiplatforms:8.1:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:a:ibm:cics_tx:11.1:*:*:*:standard:*:*:* cpe:2.3:a:ibm:cics_tx:11.1:*:*:*:advanced:*:*:* cpe:2.3:a:ibm:cics_tx:10.1:*:*:*:advanced:*:*:* cpe:2.3:a:ibm:txseries_for_multiplatforms:8.2:*:*:*:*:*:*:* |
|
CWE | CWE-311 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.7 |
References | (MISC) https://www.ibm.com/support/pages/node/7001695 - Vendor Advisory | |
References | (MISC) https://www.ibm.com/support/pages/node/7001687 - Vendor Advisory | |
References | (MISC) https://exchange.xforce.ibmcloud.com/vulnerabilities/257105 - VDB Entry, Vendor Advisory | |
References | (MISC) https://www.ibm.com/support/pages/node/7001697 - Vendor Advisory |
07 Jun 2023, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-07 22:15
Updated : 2024-02-04 23:37
NVD link : CVE-2023-33849
Mitre link : CVE-2023-33849
CVE.ORG link : CVE-2023-33849
JSON object : View
Products Affected
ibm
- txseries_for_multiplatforms
- aix
- cics_tx
linux
- linux_kernel
hp
- hp-ux
CWE
CWE-311
Missing Encryption of Sensitive Data