Skip to main content

Vendor/product archive

ibm / cics_tx CVEs

Beta · best-effort

46 CVEs tagged to ibm / cics_tx1 Critical, 6 High, 36 Medium, 3 Low, 0 Unrated.

CVE-2025-1331

Published May 8, 2025

IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the gets function.

CVSS 7.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-1330

Published May 8, 2025

IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1  could allow a local user to execute arbitrary code on the system due to failure to handle DNS return requests by…

CVSS 7.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-1329

Published May 8, 2025

IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on the system due to failure to handle DNS return requests by t…

CVSS 7.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-41746

Published Jan 16, 2025

IBM CICS TX Advanced 10.1, 11.1, and Standard 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-41745

Published Nov 1, 2024

IBM CICS TX Standard is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering th…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41744

Published Nov 1, 2024

IBM CICS TX Standard 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38360

Published Mar 4, 2024

IBM CICS TX Advanced 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functi…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38362

Published Mar 4, 2024

IBM CICS TX Advanced 10.1 could disclose sensitive information to a remote attacker due to observable discrepancy in HTTP responses. IBM X-Force ID: 260814.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34311

Published Feb 12, 2024

IBM CICS TX Standard and Advanced 11.1 could allow a user with physical access to the web browser to gain access to the user's session due to insufficiently protected credentials.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34309

Published Feb 12, 2024

IBM CICS TX Standard and Advanced 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 2…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34310

Published Feb 12, 2024

IBM CICS TX Standard and Advanced 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 2…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38361

Published Nov 18, 2023

IBM CICS TX Advanced 10.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 260770.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38364

Published Nov 13, 2023

IBM CICS TX Advanced 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functi…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38363

Published Nov 13, 2023

IBM CICS TX Advanced 10.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43018

Published Nov 3, 2023

IBM CICS TX Standard 11.1 and Advanced 10.1, 11.1 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplif…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34318

Published Dec 12, 2022

IBM CICS TX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit t…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34320

Published Nov 14, 2022

IBM CICS TX 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 229464.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 46 CVEsPage 1 of 2