Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in IBM CICS TX Standard and IBM CICS TX Advanced - CVE-2022-34313
Published: November 21, 2022 / Updated: November 21, 2022
IBM CICS TX Standard
IBM CICS TX Advanced
IBM Corporation
Description
The vulnerability allows a remote attacker to obtain sensitive cookie values.
The vulnerability exists due to IBM CICS TX does not set the secure attribute on authorization tokens or session cookies. A remote attacker can trick the victim into visiting the web application via insecure HTTP protocol and intercept sensitive cookie values.