CVE-2021-38928: IBM Sterling B2B Integrator Standard Edition cross-origin resource sharing
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Force ID: 210323.
Other sources
IBM Sterling B2B Integrator Standard Edition uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-38928.
How does IBM Sterling B2B Integrator Standard Edition use Cross-Origin Resource Sharing (CORS)?
IBM Sterling B2B Integrator Standard Edition uses Cross-Origin Resource Sharing (CORS) to allow requests from different domains.
What are the affected versions of IBM Sterling B2B Integrator Standard Edition?
The affected versions of IBM Sterling B2B Integrator Standard Edition are 6.0.0.0 through 6.0.3.7, 6.1.0.0 through 6.1.0.6, 6.1.1.0 through 6.1.1.2, and 6.1.2.0.
What could an attacker potentially do with this vulnerability?
An attacker could carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains.
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is medium with a CVSS score of 5.4.