CVE-2022-22371: IBM Sterling B2B Integrator Standard Edition session fixation
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 221195.
Other sources
IBM Sterling B2B Integrator Standard Edition does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for IBM Sterling B2B Integrator Standard Edition?
The vulnerability ID for IBM Sterling B2B Integrator Standard Edition is CVE-2022-22371.
What is the severity of CVE-2022-22371?
CVE-2022-22371 has a severity rating of 6.5 (medium).
How does IBM Sterling B2B Integrator Standard Edition handle session invalidation after a password change?
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 does not invalidate session after a password change, allowing an authenticated user to impersonate another user on the system.
Which versions of IBM Sterling B2B Integrator Standard Edition are affected by CVE-2022-22371?
IBM Sterling B2B Integrator Standard Edition versions 6.0.0.0 through 6.1.2.1 are affected by CVE-2022-22371.
How can I fix the vulnerability in IBM Sterling B2B Integrator Standard Edition?
To fix the vulnerability in IBM Sterling B2B Integrator Standard Edition, upgrade to a version higher than 6.1.2.1.