Session Cookie Vulnerability in IBM CICS TX 11.1
CVE-2022-34307
4.3MEDIUM
What is CVE-2022-34307?
IBM CICS TX 11.1 suffers from a vulnerability that fails to apply the secure attribute to authorization tokens and session cookies. This oversight allows malicious actors to potentially intercept cookie values through insecure HTTP links. By tricking users into visiting vulnerable sites or sending them deceptive links, attackers can obtain sensitive session information, leading to unauthorized access and potential data breaches.
Affected Version(s)
CICS TX Advanced 11.1
CICS TX Standard 11.1