IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the gets function.
Solution:
The product calls a function that can never be guaranteed to work safely.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/7232923 | vendor advisory |
https://www.ibm.com/support/pages/node/7232924 | vendor advisory |