IBM CICS Transaction Gateway for Multiplatforms 9.3 and 10.1 could allow a user to transfer or view files due to improper access controls.
Advisories

No advisories yet.

Fixes

Solution

IBM strongly recommends addressing the vulnerabilities now by configuring proper egress/ingress policies at either the POD or HOST level.  More details as to how to do this are described in the following CICS Transaction Gateway for Multiplatforms documentation. ProductVRMFRemediation/First FixCICS Transaction Gateway for Multiplatforms9.3Refer to this  documentation https://www.ibm.com/docs/en/cics-tg-multi/9.3.0 CICS Transaction Gateway for Multiplatforms10.1Refer to this  documentation https://www.ibm.com/docs/en/cics-tg-multi/10.1.0


Workaround

No workaround given by the vendor.

History

Fri, 13 Mar 2026 20:30:00 +0000

Type Values Removed Values Added
Description IBM CICS Transaction Gateway for Multiplatforms 9.3 and 10.1 could allow a user to transfer or view files due to improper access controls.
Title IBM CICS Transaction Gateway for Multiplatforms Information Disclosure
First Time appeared Ibm
Ibm cics Transaction Gateway
Weaknesses CWE-284
CPEs cpe:2.3:a:ibm:cics_transaction_gateway:10.1:*:*:*:*:multiplatforms:*:*
cpe:2.3:a:ibm:cics_transaction_gateway:9.3:*:*:*:*:multiplatforms:*:*
Vendors & Products Ibm
Ibm cics Transaction Gateway
References
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-03-13T20:11:00.825Z

Reserved: 2026-01-15T06:53:02.974Z

Link: CVE-2026-0977

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses