IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 could disclose sensitive path information to an attacker that could reveal through debugging or error messages.
History

Fri, 22 Nov 2024 12:00:00 +0000

Type Values Removed Values Added
References

Wed, 23 Oct 2024 11:45:00 +0000

Type Values Removed Values Added
References

Wed, 23 Oct 2024 11:15:00 +0000

Type Values Removed Values Added
Description IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. IBM X-Force ID: 273612. IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 could disclose sensitive path information to an attacker that could reveal through debugging or error messages.
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2024-03-31T12:00:11.233Z

Updated: 2024-10-23T10:59:46.860Z

Reserved: 2023-12-07T01:29:00.310Z

Link: CVE-2023-50311

cve-icon Vulnrichment

Updated: 2024-08-02T22:16:46.217Z

cve-icon NVD

Status : Modified

Published: 2024-03-31T12:15:49.340

Modified: 2024-11-21T08:36:50.263

Link: CVE-2023-50311

cve-icon Redhat

No data.