CVE-2023-42027 is a Cross-Site Request Forgery (CSRF) vulnerability affecting IBM CICS TX Standard 11.1, Advanced 10.1, 11.1, and TXSeries for Multiplatforms 8.1, 8.2, 9.1. This allows an attacker to trick a trusted user into executing unauthorized actions. With a CVSS score of 8.8 (High), the vulnerability is network-exploitable with low attack complexity, requiring user interaction, and can lead to high impacts on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, though it has received limited media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.1CPE matchmatch criteria | cpe:2.3:a:ibm:txseries_for_multiplatforms:8.1:*:*:*:*:*:*:* | ||
9.1CPE matchmatch criteria | cpe:2.3:a:ibm:txseries_for_multiplatforms:9.1:*:*:*:*:*:*:* | ||
10.1CPE matchmatch criteria | cpe:2.3:a:ibm:cics_tx:10.1:*:*:*:advanced:*:*:* | ||
11.1CPE matchmatch criteria | cpe:2.3:a:ibm:cics_tx:11.1:*:*:*:advanced:*:*:* | ||
11.1CPE matchmatch criteria | cpe:2.3:a:ibm:cics_tx:11.1:*:*:*:standard:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.