Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in IBM CICS TX Standard and IBM CICS TX Advanced - CVE-2022-34313
Published: November 21, 2022 / Updated: November 21, 2022
Vulnerability details
The vulnerability allows a remote attacker to obtain sensitive cookie values.
The vulnerability exists due to IBM CICS TX does not set the secure attribute on authorization tokens or session cookies. A remote attacker can trick the victim into visiting the web application via insecure HTTP protocol and intercept sensitive cookie values.
Affected software
IBM CICS TX Advanced
How to mitigate CVE-2022-34313
IBM CICS TX Advanced - update to 11.1.0.0 ifix5