IBM CICS TX Standard and Advanced 11.1 could allow a user with physical access to the web browser to gain access to the user's session due to insufficiently protected credentials. IBM X-Force ID: 229446.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/6832930 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/229446 | vdb entry |
https://www.ibm.com/support/pages/node/6832928 | vendor advisory |