HTML Injection Vulnerability in IBM CICS TX Standard and Advanced Products
CVE-2022-34160

5.4MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
8 July 2022

Summary

IBM CICS TX Standard and Advanced 11.1 is susceptible to an HTML injection flaw that allows remote attackers to inject malicious HTML code. When users access compromised content, this code executes within their web browser's security context of the hosting site, potentially leading to unauthorized actions and data exposure.

Affected Version(s)

CICS TX Advanced 11.1

CICS TX Standard 11.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.