Show filters
170 Total Results
Displaying 21-30 of 170
Sort by:
Attacker Value
Unknown
CVE-2023-42016
Disclosure Date: February 09, 2024 (last updated February 15, 2024)
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 265559.
0
Attacker Value
Unknown
CVE-2023-32341
Disclosure Date: February 09, 2024 (last updated February 15, 2024)
IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 255827.
0
Attacker Value
Unknown
CVE-2023-25682
Disclosure Date: November 22, 2023 (last updated November 30, 2023)
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 247034.
0
Attacker Value
Unknown
CVE-2022-35638
Disclosure Date: November 22, 2023 (last updated November 30, 2023)
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230824.
0
Attacker Value
Unknown
CVE-2023-22876
Disclosure Date: March 15, 2023 (last updated November 08, 2023)
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.1 could allow a privileged user to obtain sensitive information that could aid in further attacks against the system. IBM X-Force ID: 244364.
0
Attacker Value
Unknown
CVE-2022-43578
Disclosure Date: February 22, 2023 (last updated November 08, 2023)
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 238683.
0
Attacker Value
Unknown
CVE-2022-43579
Disclosure Date: February 17, 2023 (last updated November 08, 2023)
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 238684.
0
Attacker Value
Unknown
CVE-2022-40231
Disclosure Date: February 17, 2023 (last updated November 08, 2023)
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 could allow an authenticated user to perform unauthorized actions due to improper access controls. IBM X-Force ID: 235533.
0
Attacker Value
Unknown
CVE-2022-40232
Disclosure Date: February 17, 2023 (last updated November 08, 2023)
IBM Sterling B2B Integrator Standard Edition 6.1.0.0 through 6.1.1.1, and 6.1.2.0 could allow an authenticated user to perform actions they should not have access to due to improper permission controls. IBM X-Force ID: 235597.
0
Attacker Value
Unknown
CVE-2022-34330
Disclosure Date: January 05, 2023 (last updated November 08, 2023)
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 229469.
0