VulnerabilityModified
CVE-2022-34316
IBM CICS TX 11.1 does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers.
MEDIUM 5.3EPSS 0.66%
Does this matter?
Lower severity and a low EPSS score (0.66%). Track it; it rarely justifies an emergency change on its own.
Description
IBM CICS TX 11.1 does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers. IBM X-Force ID: 229452.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.66% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-644, CWE-116
- Affected
- ibm/cics tx
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/229452VDB Entry
- https://www.ibm.com/support/pages/node/6833176Patch, Vendor Advisory
- https://www.ibm.com/support/pages/node/6833178Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/229452VDB Entry
- https://www.ibm.com/support/pages/node/6833176Patch, Vendor Advisory
- https://www.ibm.com/support/pages/node/6833178Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.