CVE-2021-38928

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Force ID: 210323.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:standard:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:standard:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:standard:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.1.2.0:*:*:*:standard:*:*:*

History

21 Nov 2024, 06:18

Type Values Removed Values Added
Summary
  • (es) Las versiones de IBM Sterling B2B Integrator Standard Edition de la 6.0.0.0 a la 6.1.2.1 utiliza el uso compartido de recursos entre orígenes (CORS), lo que podría permitir a un atacante llevar a cabo acciones privilegiadas y recuperar información confidencial, ya que el nombre de dominio no se limita solo a dominios confiables. ID de IBM X-Force: 210323.
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/210323 - VDB Entry, Vendor Advisory () https://exchange.xforce.ibmcloud.com/vulnerabilities/210323 - VDB Entry, Vendor Advisory
References () https://www.ibm.com/support/pages/node/6852467 - Vendor Advisory () https://www.ibm.com/support/pages/node/6852467 - Vendor Advisory

Information

Published : 2023-01-04 18:15

Updated : 2024-11-21 06:18


NVD link : CVE-2021-38928

Mitre link : CVE-2021-38928

CVE.ORG link : CVE-2021-38928


JSON object : View

Products Affected

ibm

  • sterling_b2b_integrator