CVE-2022-35638: IBM Sterling B2B Integrator cross-site request forgery
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230824.
Other sources
IBM Sterling B2B Integrator Standard Edition is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
CVE-2022-35638
What is the severity of CVE-2022-35638?
The severity of CVE-2022-35638 is medium with a severity value of 4.3.
Which software versions are affected by CVE-2022-35638?
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 are affected by CVE-2022-35638.
What is cross-site request forgery?
Cross-site request forgery (CSRF) is an attack that tricks the victim into submitting a malicious request, unknowingly executing unwanted actions on a website or web application.
How can the CVE-2022-35638 vulnerability be fixed?
To fix the CVE-2022-35638 vulnerability, users should update IBM Sterling B2B Integrator to versions 6.0.3.9 or 6.1.2.2 or apply the necessary patches as recommended by IBM.