CVE-2022-35638
- EPSS 0.04%
- Veröffentlicht 22.11.2023 04:15:07
- Zuletzt bearbeitet 21.11.2024 07:11:24
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the ...
CVE-2023-22876
- EPSS 0.09%
- Veröffentlicht 15.03.2023 19:15:24
- Zuletzt bearbeitet 21.11.2024 07:45:33
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.1 could allow a privileged user to obtain sensitive information that could aid in further attacks against the system. IBM X-Force ID: 244364.
CVE-2022-43578
- EPSS 0.12%
- Veröffentlicht 22.02.2023 18:15:10
- Zuletzt bearbeitet 21.11.2024 07:26:49
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functi...
CVE-2022-40231
- EPSS 0.07%
- Veröffentlicht 17.02.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:21:07
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 could allow an authenticated user to perform unauthorized actions due to improper access controls. IBM X-Force ID: 235533.
CVE-2022-43579
- EPSS 0.22%
- Veröffentlicht 17.02.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:26:49
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functi...
CVE-2022-40232
- EPSS 0.06%
- Veröffentlicht 17.02.2023 18:15:11
- Zuletzt bearbeitet 21.11.2024 07:21:07
IBM Sterling B2B Integrator Standard Edition 6.1.0.0 through 6.1.1.1, and 6.1.2.0 could allow an authenticated user to perform actions they should not have access to due to improper permission controls. IBM X-Force ID: 235597.
CVE-2022-22371
- EPSS 0.04%
- Veröffentlicht 05.01.2023 07:15:09
- Zuletzt bearbeitet 21.11.2024 06:46:43
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 221195.
CVE-2022-34330
- EPSS 0.16%
- Veröffentlicht 05.01.2023 07:15:09
- Zuletzt bearbeitet 21.11.2024 07:09:18
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading ...
CVE-2022-43920
- EPSS 0.1%
- Veröffentlicht 04.01.2023 18:15:09
- Zuletzt bearbeitet 21.11.2024 07:27:21
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 could allow an authenticated user to gain privileges in a different group due to an access control vulnerability in the Sftp server adapter. IBM X-Force ID: 241362.
CVE-2021-38928
- EPSS 0.09%
- Veröffentlicht 04.01.2023 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:18:13
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to...