Description
IBM CICS Transaction Gateway for Multiplatforms 9.3 and 10.1 could allow a user to transfer or view files due to improper access controls.
Published: 2026-03-13
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure due to improper access controls
Action: Configure Policies
AI Analysis

Impact

The vulnerability arises from improper access controls in IBM CICS Transaction Gateway for Multiplatforms, allowing users to transfer or view files they should not have access to. This flaw results in the unauthorized disclosure of information and is aligned with CWE‑284 (Improper Restriction of Operations within the Bounds of a Function). The potential impact is the exposure of sensitive data stored or transmitted through the gateway, affecting confidentiality.

Affected Systems

IBM CICS Transaction Gateway for Multiplatforms versions 9.3 and 10.1 deployed in multiplatform environments are affected. The issue applies to installations referenced by the CPE strings for 9.3 and 10.1.

Risk and Exploitability

The CVSS score is 5.1 (medium), and the EPSS score is under 1%, indicating a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack could be carried out by authenticated users who have access to the gateway’s file operations, or potentially by any user in the same environment if additional privilege escalations occur. Proper ingress/egress policies at the pod or host level help mitigate the risk.

Generated by OpenCVE AI on April 2, 2026 at 15:52 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by configuring proper egress/ingress policies at either the POD or HOST level.  More details as to how to do this are described in the following CICS Transaction Gateway for Multiplatforms documentation. ProductVRMFRemediation/First FixCICS Transaction Gateway for Multiplatforms9.3Refer to this  documentation https://www.ibm.com/docs/en/cics-tg-multi/9.3.0 CICS Transaction Gateway for Multiplatforms10.1Refer to this  documentation https://www.ibm.com/docs/en/cics-tg-multi/10.1.0


OpenCVE Recommended Actions

  • Apply the IBM‑recommended configuration changes to enforce proper egress/ingress policies at the pod or host level as documented by IBM.
  • Verify that file transfer and view functionalities are restricted to authorized users and that permission checks are enforced.
  • Monitor system logs for unauthorized file access attempts and investigate anomalies promptly.

Generated by OpenCVE AI on April 2, 2026 at 15:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-Other

Mon, 16 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 13 Mar 2026 20:30:00 +0000

Type Values Removed Values Added
Description IBM CICS Transaction Gateway for Multiplatforms 9.3 and 10.1 could allow a user to transfer or view files due to improper access controls.
Title IBM CICS Transaction Gateway for Multiplatforms Information Disclosure
First Time appeared Ibm
Ibm cics Transaction Gateway
Weaknesses CWE-284
CPEs cpe:2.3:a:ibm:cics_transaction_gateway:10.1:*:*:*:*:multiplatforms:*:*
cpe:2.3:a:ibm:cics_transaction_gateway:9.3:*:*:*:*:multiplatforms:*:*
Vendors & Products Ibm
Ibm cics Transaction Gateway
References
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Ibm Cics Transaction Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-03-16T20:10:20.798Z

Reserved: 2026-01-15T06:53:02.974Z

Link: CVE-2026-0977

cve-icon Vulnrichment

Updated: 2026-03-16T20:10:16.092Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-16T14:18:07.810

Modified: 2026-04-02T14:08:57.950

Link: CVE-2026-0977

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-02T20:23:48Z

Weaknesses