VYPR
Unrated severityNVD Advisory· Published Nov 14, 2022· Updated Apr 25, 2025

IBM CICS TX information disclosure

CVE-2022-34329

Description

IBM CICS TX 11.7 could allow an attacker to obtain sensitive information from HTTP response headers. IBM X-Force ID: 229467.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

In IBM CICS TX, HTTP responses may include sensitive information due to improper handling, allowing remote attackers to obtain it.

Vulnerability

IBM CICS TX Advanced 11.1 and IBM CICS TX Standard all versions may leak sensitive information in HTTP response headers [1][2]. The vulnerability exists because the software does not properly sanitize or control the contents of HTTP headers, potentially exposing internal details or credentials to network adversaries.

Exploitation

An attacker with network access to the affected CICS TX system can send HTTP requests and observe the responses. No authentication or user interaction is required; the attack is remote and low-complexity [1][2]. By analyzing the HTTP response headers, the attacker can extract sensitive information.

Impact

Successful exploitation leads to information disclosure, specifically low confidentiality impact as per CVSS [1]. The attacker may obtain sensitive data embedded in HTTP headers, such as session tokens or internal configuration details, which could be used to further compromise the application or network.

Mitigation

IBM has released interim fixes for both IBM CICS TX Advanced 11.1 and IBM CICS TX Standard 11.1 [1][2]. The fix addresses the information disclosure by removing sensitive data from HTTP headers. Customers should apply the appropriate fix from IBM Fix Central and review the security bulletin for instructions. No workarounds are available.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • IBM/CICS TXllm-fuzzy2 versions
    = 11.7+ 1 more
    • (no CPE)range: = 11.7
    • (no CPE)range: 11.7

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.