CVE-2023-42011

MEDIUM

IBM Sterling B2B Integrator Standard Edition 6.1-6.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM Sterling B2B Integrator Standard Edition 6.1 and 6.2 does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with. IBM X-Force ID: 265508.

Scores

CVSS v3 4.3
EPSS 0.0005
EPSS Percentile 16.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1021
Status published
Products (2)
ibm/sterling_b2b_integrator 6.1
ibm/sterling_b2b_integrator 6.2
Published Jun 27, 2024
Tracked Since Feb 18, 2026