VYPR
Unrated severityNVD Advisory· Published Nov 14, 2022· Updated Apr 30, 2025

IBM CICS TX clickjacking

CVE-2022-34318

Description

IBM CICS TX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 229461.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM CICS TX 11.1 (Advanced and Standard) is vulnerable to clickjacking, allowing a remote attacker to hijack victim's click actions via a malicious website.

Vulnerability

IBM CICS TX Advanced 11.1 and IBM CICS TX Standard (all versions, specifically 11.1) are vulnerable to a clickjacking attack (CVE-2022-34318). The vulnerability allows a remote attacker to hijack the clicking action of a victim by persuading them to visit a malicious website [1][2].

Exploitation

An attacker must convince a victim to visit a crafted malicious website. The victim must be authenticated to the CICS TX application (CVSS PR:L indicates low privileges required for the attacker, but the attack vector is network-based with low complexity). Once the victim interacts with the malicious page, the attacker can hijack click actions, potentially tricking the victim into performing unintended actions within the CICS TX interface [1][2].

Impact

Successful exploitation allows the attacker to hijack the victim's click actions, leading to low confidentiality and low integrity impact with a changed scope (CVSS 5.4). This could enable further attacks such as unauthorized transactions or information disclosure, depending on the victim's privileges [1][2].

Mitigation

IBM has released interim fixes for both IBM CICS TX Advanced 11.1 and IBM CICS TX Standard 11.1. The fixes are available for download from IBM support [1][2]. No workarounds are provided; applying the fix is recommended.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • IBM/CICS TXllm-fuzzy2 versions
    = 11.1+ 1 more
    • (no CPE)range: = 11.1
    • (no CPE)range: 11.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.