CVE-2023-42016 – IBM Sterling B2B Integrator information disclosure
https://notcve.org/view.php?id=CVE-2023-42016
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 265559. IBM Sterling B2B Integrator Standard Edition 6.0.0.0 a 6.0.3.8 y 6.1.0.0 a 6.1.2.3 no establece el atributo seguro en tokens de autorización o cookies de sesión. • https://exchange.xforce.ibmcloud.com/vulnerabilities/265559 https://www.ibm.com/support/pages/node/7116083 • CWE-319: Cleartext Transmission of Sensitive Information CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute •
CVE-2023-32341 – IBM Sterling B2B Integrator denial of service
https://notcve.org/view.php?id=CVE-2023-32341
IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 255827. IBM Sterling B2B Integrator 6.0.0.0 a 6.0.3.8 y 6.1.0.0 a 6.1.2.3 podría permitir que un usuario autenticado provoque una denegación de servicio debido al consumo incontrolado de recursos. ID de IBM X-Force: 255827. • https://exchange.xforce.ibmcloud.com/vulnerabilities/255827 https://www.ibm.com/support/pages/node/7116081 • CWE-400: Uncontrolled Resource Consumption •
CVE-2023-25682 – IBM Sterling B2B Integrator information disclosure
https://notcve.org/view.php?id=CVE-2023-25682
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 247034. IBM Sterling B2B Integrator Standard Edition 6.0.0.0 a 6.0.3.8 y 6.1.0.0 a 6.1.2.1 almacena información potencialmente confidencial en archivos de registro que un usuario local podría leer. ID de IBM X-Force: 247034. • https://exchange.xforce.ibmcloud.com/vulnerabilities/247034 https://www.ibm.com/support/pages/node/7080172 • CWE-532: Insertion of Sensitive Information into Log File •
CVE-2022-35638 – IBM Sterling B2B Integrator cross-site request forgery
https://notcve.org/view.php?id=CVE-2022-35638
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230824. IBM Sterling B2B Integrator Standard Edition 6.0.0.0 a 6.0.3.8 y 6.1.0.0 a 6.1.2.1 es vulnerable a cross-site request forgery, lo que podría permitir a un atacante ejecutar acciones maliciosas y no autorizadas transmitidas por un usuario en el que confía el sitio web. ID de IBM X-Force: 230824. • https://exchange.xforce.ibmcloud.com/vulnerabilities/230824 https://www.ibm.com/support/pages/node/7080104 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2023-22876 – IBM Sterling B2B Integrator information disclosure
https://notcve.org/view.php?id=CVE-2023-22876
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.1 could allow a privileged user to obtain sensitive information that could aid in further attacks against the system. IBM X-Force ID: 244364. • https://exchange.xforce.ibmcloud.com/vulnerabilities/244364 https://www.ibm.com/support/pages/node/6963093 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •