CVE-2022-34307
Last modified
CVE-2022-34307 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 229436.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Cics Tx | 11.1 |
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/229436VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6608208Patch, Vendor Advisory
- https://www.ibm.com/support/pages/node/6608210Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/229436VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6608208Patch, Vendor Advisory
- https://www.ibm.com/support/pages/node/6608210Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-34307?
How severe is CVE-2022-34307?
How do I fix CVE-2022-34307?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-34300In tinyexr 1.0.1, there is a heap-based buffer over-read in …8.8
- CVE-2022-34301A flaw was found in CryptoPro Secure Disk bootloaders before…6.7
- CVE-2022-34302A flaw was found in New Horizon Datasys bootloaders before 2…6.7
- CVE-2022-34303A flaw was found in Eurosoft bootloaders before 2022-06-01. …6.7
- CVE-2022-34305In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.…6.1
- CVE-2022-34306IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTTP…5.4
- CVE-2022-34308IBM CICS TX 11.1 could allow a local user to cause a denial …5.5
- CVE-2022-34309IBM CICS TX Standard and Advanced 11.1 uses weaker than expe…7.5
- CVE-2022-3431A potential vulnerability in a driver used during manufactur…7.8
- CVE-2022-34310IBM CICS TX Standard and Advanced 11.1 uses weaker than expe…7.5
- CVE-2022-34311IBM CICS TX Standard and Advanced 11.1 could allow a user wi…4.3
- CVE-2022-34312 IBM CICS TX 11.1 allows web pages to be stored locally whic…3.3
Are you affected by CVE-2022-34307?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
