VYPR
Unrated severityNVD Advisory· Published Nov 14, 2022· Updated Apr 30, 2025

IBM CICS TX information disclosure

CVE-2022-34312

Description

IBM CICS TX 11.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 229447.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM CICS TX Standard and Advanced 11.1 store web pages locally, allowing other local users to read potentially sensitive data without authentication.

Vulnerability

IBM CICS TX Standard and Advanced version 11.1 have a vulnerability where web pages are stored in a local filesystem location that can be accessed by other users on the same system [1, 2]. This affects the default configuration and requires no special authentication to exploit if an attacker has local access.

Exploitation

An attacker with local system access (e.g., a non-privileged user on the same machine) can browse to the directory where web pages are stored and read them [1, 2]. No network-level privileges or user interaction is needed beyond having a local account on the system.

Impact

Successful exploitation allows an attacker to read cached or stored web pages, which may contain sensitive information such as authentication tokens, session data, or other confidential content. The CVSS 3.0 vector (AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) indicates low confidentiality impact with no integrity or availability impact [1, 2].

Mitigation

IBM has released interim fixes for both products. For IBM CICS TX Advanced 11.1, download the fix from the IBM support page referenced as defect 127903 [1]. For IBM CICS TX Standard 11.1, download the fix from the IBM support page referenced as defect 127902 [2]. No workarounds are available [1, 2].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • IBM/CICS TXllm-fuzzy2 versions
    = 11.1+ 1 more
    • (no CPE)range: = 11.1
    • (no CPE)range: 11.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.