PT-2022-15462 · Ibm · Ibm Sterling B2B Integrator Standard Edition

Published

2022-05-17

·

Updated

2022-05-26

·

CVE-2022-22482

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions IBM Sterling B2B Integrator Standard Edition versions 6.0.0.0 through 6.0.3.5 IBM Sterling B2B Integrator Standard Edition versions 6.1.0.0 through 6.1.1.0
Description The issue allows an authenticated user to upload files that could fill up the filesystem and cause a denial of service.
Recommendations For versions 6.0.0.0 through 6.0.3.5, consider restricting file upload capabilities to prevent denial of service. For versions 6.1.0.0 through 6.1.1.0, consider restricting file upload capabilities to prevent denial of service. As a temporary workaround, consider disabling file upload functionality until a patch is available.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-22482

Affected Products

Ibm Sterling B2B Integrator Standard Edition