CVE-2023-50311

LOW

IBM Cics Transaction Gateway - Insufficiently Protected Credentials

Title source: rule

Description

IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 could disclose sensitive path information to an attacker that could reveal through debugging or error messages.

Scores

CVSS v3 3.1
EPSS 0.0005
EPSS Percentile 16.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-522
Status published

Affected Products (2)

ibm/cics_transaction_gateway
ibm/cics_transaction_gateway

Timeline

Published Mar 31, 2024
Tracked Since Feb 18, 2026