CVE-2023-50310

MEDIUM

IBM CICS Transaction Gateway 9.2-9.3 - Insufficiently Protected Credentials

Title source: llm
STIX 2.1

Description

IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

References (1)

Core 1
Core References

Scores

CVSS v3 4.9
EPSS 0.0011
EPSS Percentile 28.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-522
Status published
Products (2)
ibm/cics_transaction_gateway 9.2
ibm/cics_transaction_gateway 9.3
Published Oct 23, 2024
Tracked Since Feb 18, 2026