Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in IBM CICS TX Standard and IBM CICS TX Advanced - CVE-2022-34313

 

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in IBM CICS TX Standard and IBM CICS TX Advanced - CVE-2022-34313

Published: November 21, 2022 / Updated: November 21, 2022


Vulnerability identifier: #VU69436
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-34313
CWE-ID: CWE-614
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain sensitive cookie values.

The vulnerability exists due to IBM CICS TX does not set the secure attribute on authorization tokens or session cookies. A remote attacker can trick the victim into visiting the web application via insecure HTTP protocol and intercept sensitive cookie values.


Affected software

IBM CICS TX Standard
IBM CICS TX Advanced

How to mitigate CVE-2022-34313

Install updates from vendor's website.

IBM CICS TX Standard - update to 11.1.0.0 ifix5
IBM CICS TX Advanced - update to 11.1.0.0 ifix5

External References

Related Security Bulletins