First published: Wed Mar 13 2024(Updated: )
IBM Integration Bus for z/OS 10.1 through 10.1.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 284564.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Integration Bus | <=10.1 - 10.1.0.3 | |
All of | ||
IBM Integration Bus for z/OS | >=10.1<=10.1.0.3 | |
Any of | ||
IBM z/OS | ||
Linux Kernel | ||
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-27265 is classified as a high severity vulnerability due to the potential for cross-site request forgery attacks.
To fix CVE-2024-27265, users should apply the latest patches from IBM for the Integration Bus for z/OS.
CVE-2024-27265 affects IBM Integration Bus for z/OS versions 10.1 through 10.1.0.3.
CVE-2024-27265 enables cross-site request forgery, allowing attackers to perform unauthorized actions on behalf of trusted users.
Failing to address CVE-2024-27265 may lead to unauthorized actions being executed by an attacker using a trusted user's credentials.