Cross-site request forgery in IBM Corporation products - CVE-2023-42027
Published: December 18, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists due to insufficient validation of the HTTP request origin. A remote attacker can trick the victim to visit a specially crafted web page and execute malicious and unauthorized actions transmitted from a user that the website trusts.
Affected software
IBM CICS TX Advanced
IBM CICS TX Standard
How to mitigate CVE-2023-42027
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix22, 11.1.0.0 ifix14
IBM CICS TX Standard - update to 11.1.0.0 ifix14