Impact
The vulnerability arises from improper access controls in IBM CICS Transaction Gateway for Multiplatforms, allowing users to transfer or view files they should not have access to. This flaw results in the unauthorized disclosure of information and is aligned with CWE‑284 (Improper Restriction of Operations within the Bounds of a Function). The potential impact is the exposure of sensitive data stored or transmitted through the gateway, affecting confidentiality.
Affected Systems
IBM CICS Transaction Gateway for Multiplatforms versions 9.3 and 10.1 deployed in multiplatform environments are affected. The issue applies to installations referenced by the CPE strings for 9.3 and 10.1.
Risk and Exploitability
The CVSS score is 5.1 (medium), and the EPSS score is under 1%, indicating a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack could be carried out by authenticated users who have access to the gateway’s file operations, or potentially by any user in the same environment if additional privilege escalations occur. Proper ingress/egress policies at the pod or host level help mitigate the risk.
OpenCVE Enrichment