CVE-2024-27265: IBM Integration Bus for z/OS cross-site request forgery
IBM Integration Bus for z/OS 10.1 through 10.1.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 284564.
Other sources
IBM Integration Bus for z/OS is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27265?
CVE-2024-27265 is classified as a high severity vulnerability due to the potential for cross-site request forgery attacks.
How do I fix CVE-2024-27265?
To fix CVE-2024-27265, users should apply the latest patches from IBM for the Integration Bus for z/OS.
What products are affected by CVE-2024-27265?
CVE-2024-27265 affects IBM Integration Bus for z/OS versions 10.1 through 10.1.0.3.
What type of attack does CVE-2024-27265 enable?
CVE-2024-27265 enables cross-site request forgery, allowing attackers to perform unauthorized actions on behalf of trusted users.
What are the implications of not addressing CVE-2024-27265?
Failing to address CVE-2024-27265 may lead to unauthorized actions being executed by an attacker using a trusted user's credentials.