IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 3.7epss 0.3%
exploitation probability
0.3%top 79% of all CVEs
observed exploitation
nono source reports it
In short
IBM Sterling B2B Integrator and File Gateway have a cookie security flaw that could expose sensitive information. The cookie lacks proper protection settings, allowing attackers in certain scenarios to access data they shouldn't.
Technical detail
The affected versions (6.0.0.0-6.1.2.7, 6.2.0.0-6.2.0.5, 6.2.1.1) fail to set the SameSite attribute on a sensitive cookie, enabling potential cross-site request forgery (CSRF) or cross-site script inclusion attacks to leak session data. Exploitation requires user interaction in a cross-site context.
Summary generated and translated by AI from the official description.
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N