CVE-2021-38928

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Force ID: 210323.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:standard:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:standard:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:standard:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.1.2.0:*:*:*:standard:*:*:*

History

07 Nov 2023, 03:37

Type Values Removed Values Added
Summary IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Force ID: 210323. IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Force ID: 210323.

11 Jan 2023, 02:59

Type Values Removed Values Added
First Time Ibm
Ibm sterling B2b Integrator
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CPE cpe:2.3:a:ibm:sterling_b2b_integrator:6.1.2.0:*:*:*:standard:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:standard:*:*:*
CWE NVD-CWE-noinfo
References (MISC) https://exchange.xforce.ibmcloud.com/vulnerabilities/210323 - (MISC) https://exchange.xforce.ibmcloud.com/vulnerabilities/210323 - VDB Entry, Vendor Advisory
References (MISC) https://www.ibm.com/support/pages/node/6852467 - (MISC) https://www.ibm.com/support/pages/node/6852467 - Vendor Advisory

04 Jan 2023, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-04 18:15

Updated : 2023-12-10 14:48


NVD link : CVE-2021-38928

Mitre link : CVE-2021-38928

CVE.ORG link : CVE-2021-38928


JSON object : View

Products Affected

ibm

  • sterling_b2b_integrator