IBM CICS TX information disclosure
Description
IBM CICS TX 11.1 does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers. IBM X-Force ID: 229452.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CVE-2022-34316 describes a reflected XSS vulnerability in IBM CICS TX due to unprotected HTTP headers, affecting versions 11.1 of Standard and Advanced.
Vulnerability
IBM CICS TX versions 11.1 (both Standard and Advanced) fail to neutralize or incorrectly neutralize web scripting syntax in HTTP headers that can be processed by web browser components [1][2]. This is a reflected cross-site scripting (XSS) issue in the HTTP response header handling [1][2].
Exploitation
An attacker can craft a malicious link or script payload that, when visited by a user via a web browser, results in the execution of JavaScript within the user's session [1][2]. The attacker does not require authentication, but the attack requires user interaction (clicking a crafted link or visiting a malicious page) [1][2]. The attack vector is network-based with a CVSS vector of AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N [1][2].
Impact
Successful exploitation leads to limited information disclosure (confidentiality impact: Low) as the attacker can read browser-accessible data, such as session tokens or cookies, within the targeted user's session [1][2]. There is no integrity or availability impact per the CVSS score [1][2]. The scope remains unchanged (S:U), meaning the attacker cannot pivot to other resources [1][2].
Mitigation
IBM released fixes for both affected products on 31 October 2022 [1][2]. For IBM CICS TX Standard version 11.1, a download fix is available for defect 127920 [2]; for IBM CICS TX Advanced version 11.1, a download fix is available for the same defect [1]. No workarounds or mitigations were provided [1][2].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.ibm.com/support/pages/node/6833176mitrevendor-advisory
- www.ibm.com/support/pages/node/6833178mitrevendor-advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/229452mitrevdb-entry
News mentions
0No linked articles in our index yet.