First published: Tue Dec 27 2022(Updated: )
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Force ID: 210323.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling B2B Integrator | >=6.0.0.0<6.0.3.7 | |
IBM Sterling B2B Integrator | >=6.1.0.0<6.1.0.6 | |
IBM Sterling B2B Integrator | >=6.1.1.0<6.1.1.2 | |
IBM Sterling B2B Integrator | =6.1.2.0 | |
IBM Sterling B2B Integrator | <=6.0.0.0 - 6.0.3.6 | |
IBM Sterling B2B Integrator | <=6.1.0.0 - 6.1.0.5, 6..1.1.0 - 6.1.1.1, 6.1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-38928.
IBM Sterling B2B Integrator Standard Edition uses Cross-Origin Resource Sharing (CORS) to allow requests from different domains.
The affected versions of IBM Sterling B2B Integrator Standard Edition are 6.0.0.0 through 6.0.3.7, 6.1.0.0 through 6.1.0.6, 6.1.1.0 through 6.1.1.2, and 6.1.2.0.
An attacker could carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains.
The severity rating of this vulnerability is medium with a CVSS score of 5.4.