CVE-2023-42011

MEDIUM

IBM Sterling B2B Integrator Standard Edition 6.1-6.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM Sterling B2B Integrator Standard Edition 6.1 and 6.2 does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with. IBM X-Force ID: 265508.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
https://www.ibm.com/support/pages/node/7158657

Scores

CVSS v3 4.3
EPSS 0.0022
EPSS Percentile 12.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1021
Status published
Products (2)
ibm/sterling_b2b_integrator 6.1
ibm/sterling_b2b_integrator 6.2
Published Jun 27, 2024
Tracked Since Feb 18, 2026