Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-33847


IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 257102.


Published

2023-06-08T01:15:09.120

Last Modified

2024-11-21T08:06:04.123

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 3.7 (LOW)

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm txseries_for_multiplatform 8.1 Yes
Operating System ibm aix - No
Operating System linux linux_kernel - No
Application ibm txseries_for_multiplatform < 8.2.0.2 Yes
Operating System hp hp-ux - No
Operating System ibm aix - No
Operating System linux linux_kernel - No
Application ibm txseries_for_multiplatform < 9.1.0.2 Yes
Operating System ibm aix - No
Operating System linux linux_kernel - No
Application ibm cics_tx 10.1 Yes
Application ibm cics_tx 11.1 Yes
Application ibm cics_tx 11.1 Yes
Operating System linux linux_kernel - No

References