CVE Vulnerabilities

CVE-2023-43018

Improper Privilege Management

Published: Nov 03, 2023 | Modified: Nov 09, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM CICS TX Standard 11.1 and Advanced 10.1, 11.1 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 266163.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Cics_tx Ibm 10.1 (including) 10.1 (including)
Cics_tx Ibm 11.1 (including) 11.1 (including)

Potential Mitigations

References