Known vulnerabilities in CICS Transaction Gateway Desktop Edition

Software CPE: cpe:2.3:a:ibm_corporation:cics_transaction_gateway_desktop_edition:*:*:*:*:*:*:*:*
Total vulnerabilities: 153
Public exploits: 18
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting CICS Transaction Gateway Desktop Edition CICS Transaction Gateway Desktop Edition is affected by 153 known vulnerabilities: 1 critical, 16 high, 96 medium, 40 low Critical High Medium Low

Vulnerabilities (153)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU139159 - Deserialization of Untrusted Data
CVE-2026-54512
CWE-502 High
No
No
- 22.07.2026 SB2026072278
SB2026072282
SB2026072283
and 24 more
#VU139158 - Incomplete List of Disallowed Inputs
CVE-2026-54513
CWE-184 High
No
No
- 22.07.2026 SB2026072278
SB2026072282
SB2026072283
and 26 more
#VU139157 - Server-Side Request Forgery (SSRF)
CVE-2026-54514
CWE-918 Medium
No
No
- 22.07.2026 SB2026072278
SB2026072288
SB2026072340
and 10 more
#VU139156 - Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-54515
CWE-915 Medium
No
No
- 22.07.2026 SB2026072278
SB2026072282
SB2026072288
and 12 more
#VU139155 - Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-54516
CWE-915 Medium
No
No
- 22.07.2026 SB2026072278
SB2026072282
SB2026072340
and 7 more
#VU139154 - Incorrect Authorization
CVE-2026-54517
CWE-863 Medium
No
No
- 22.07.2026 SB2026072278
SB2026072282
SB2026072340
and 7 more
#VU139153 - Incorrect Authorization
CVE-2026-54518
CWE-863 Medium
No
No
- 22.07.2026 SB2026072278
SB2026072282
SB2026072340
and 7 more
#VU139152 - Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-59888
CWE-915 Medium
No
No
- 22.07.2026 SB2026072278
SB2026072413
SB20260728138
and 3 more
#VU139151 - Incorrect Authorization
CVE-2026-59889
CWE-863 Low
No
No
- 22.07.2026 SB2026072278
SB2026072413
SB20260728138
and 3 more
#VU139055 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-8646
CWE-444 High
No
No
- 22.07.2026 SB2026072215
SB2026072219
SB2026072328
and 16 more
#VU139054 - Resource exhaustion
CVE-2026-9320
CWE-400 Medium
No
No
- 22.07.2026 SB2026072214
SB2026072219
SB2026072328
and 16 more
#VU137314 - Resource exhaustion
CVE-2026-9071
CWE-400 Low
No
No
- 10.07.2026 SB2026071036
SB2026071037
SB2026072219
and 15 more
#VU135124 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-11541
CWE-444 High
No
No
- 24.06.2026 SB2026062445
SB2026062950
SB2026063026
and 18 more
#VU124831 - Weak Password Requirements
CVE-2025-14917
CWE-521 Low
No
No
- 02.04.2026 SB2026040252
SB2026040327
SB2026040328
and 18 more
#VU122999 - Improper Authorization
CVE-2026-24734
CWE-285 Medium
No
No
- 17.02.2026 SB2026021766
SB2026030536
SB2026031245
and 27 more
#VU114024 - Resource exhaustion
CVE-2025-48989
CWE-400 Medium
No
No
- 13.08.2025 SB2025081375
SB2025081376
SB20250820127
and 49 more
#VU111161 - Resource exhaustion
CVE-2025-48988
CWE-400 Medium
Available
No
- 16.06.2025 SB2025061634
SB2025061927
SB20250620145
and 40 more
#VU111160 - Untrusted Search Path
CVE-2025-49124
CWE-426 Low
No
No
- 16.06.2025 SB2025061634
SB2025061927
SB2025112459
and 4 more
#VU109959 - Improper Handling of Case Sensitivity
CVE-2025-46701
CWE-178 Low
Available
No
- 30.05.2025 SB2025053002
SB2025061335
SB2025062313
and 22 more
#VU107995 - Improper input validation
CVE-2025-31651
CWE-20 Medium
Available
No
- 28.04.2025 SB2025042851
SB2025050943
SB2025050982
and 46 more


Showing elements 1 - 20 out of 153