PT-2025-26174 · Ibm · Ibm Sterling B2B Integrator+1
CVE-2024-54172
·
Publicado
2025-06-18
·
Atualizado
2025-06-19
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Sterling B2B Integrator and IBM Sterling File Gateway versions 6.0.0.0 through 6.1.2.6
IBM Sterling B2B Integrator and IBM Sterling File Gateway versions 6.2.0.0 through 6.2.0.4
Description
The issue is related to cross-site request forgery, which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Recommendations
For versions 6.0.0.0 through 6.1.2.6, update to a version outside of this range to mitigate the risk.
For versions 6.2.0.0 through 6.2.0.4, update to a version outside of this range to mitigate the risk.
As a temporary workaround, consider implementing additional security measures to prevent cross-site request forgery attacks until a patch is available.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Sterling B2B Integrator
Ibm Sterling File Gateway