Arbitrary Code Execution Vulnerability in IBM CICS TX Products
CVE-2025-1329
7.8HIGH
Summary
IBM CICS TX Standard version 11.1 and IBM CICS TX Advanced versions 10.1 and 11.1 contain a vulnerability that could enable a local attacker to execute arbitrary code on the system. This issue arises from the improper handling of DNS return requests by the 'gethostbyaddr' function, potentially allowing unauthorized control over system functions. It is crucial for users of these products to review the advisories provided by IBM and implement necessary security measures.
Affected Version(s)
CICS TX Advanced Linux 10.1, 11.1
CICS TX Standard Linux 11.1
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved