CVE-2022-34316

IBM CICS TX 11.1 does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers. IBM X-Force ID: 229452.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:cics_tx:11.1:*:*:*:advanced:*:*:*
cpe:2.3:a:ibm:cics_tx:11.1:*:*:*:standard:*:*:*

History

21 Nov 2024, 07:09

Type Values Removed Values Added
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/229452 - VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/229452 - VDB Entry
References () https://www.ibm.com/support/pages/node/6833176 - Patch, Vendor Advisory () https://www.ibm.com/support/pages/node/6833176 - Patch, Vendor Advisory
References () https://www.ibm.com/support/pages/node/6833178 - Patch, Vendor Advisory () https://www.ibm.com/support/pages/node/6833178 - Patch, Vendor Advisory
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 3.7

07 Nov 2023, 03:48

Type Values Removed Values Added
Summary IBM CICS TX 11.1 does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers. IBM X-Force ID: 229452. IBM CICS TX 11.1 does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers. IBM X-Force ID: 229452.

Information

Published : 2022-11-14 19:15

Updated : 2024-11-21 07:09


NVD link : CVE-2022-34316

Mitre link : CVE-2022-34316

CVE.ORG link : CVE-2022-34316


JSON object : View

Products Affected

ibm

  • cics_tx
CWE
CWE-644

Improper Neutralization of HTTP Headers for Scripting Syntax

CWE-116

Improper Encoding or Escaping of Output