Lucene search

K
ibmIBM27FE9EC90D63CD567FC8724C9149F40F60FB24EF5AA79B4E1ECED78A1280CC1F
HistoryJul 11, 2023 - 10:13 a.m.

Security Bulletin: IBM Sterling Connect:Express for UNIX browser UI is vulnerable to attacks that rely on the use of cookies without the SameSite attribute

2023-07-1110:13:20
www.ibm.com
19
ibm
sterling connect:express
unix
browser ui
cookies
samesite
vulnerability
upgrade
sterling b2b integrator
fix central

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.0004 Low

EPSS

Percentile

13.1%

Summary

IBM Sterling Connect:Express for UNIX browser UI is vulnerable to attacks that rely on the use of cookies without the SameSite attribute

Vulnerability Details

CVEID:CVE-2023-29259
**DESCRIPTION:**IBM Sterling Connect:Express for UNIX browser UI is vulnerable to attacks that rely on the use of cookies without the SameSite attribute.
CVSS Base score: 3.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/252055 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
Sterling Connect:Express for UNIX 1.5.x

Remediation/Fixes

Upgrade to Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0.12 available on Fix Central

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmsterling_b2b_integratorMatch5.2
CPENameOperatorVersion
ibm sterling b2b integratoreq5.2

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.0004 Low

EPSS

Percentile

13.1%

Related for 27FE9EC90D63CD567FC8724C9149F40F60FB24EF5AA79B4E1ECED78A1280CC1F