IT

Tracker / CVE-2023-33847

CVE-2023-33847

Low 3.7

IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 257102.

Affected products and versions

ibm cics_tx
ibm txseries_for_multiplatform
ibm txseries_for_multiplatform · 8.2 → 8.2.0.2
ibm txseries_for_multiplatform · 9.1 → 9.1.0.2

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References