SB2022101806 - Input validation error in IBM Sterling B2B Integrator
Published: October 18, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2021-22060)
The vulnerability allows a remote attacker to modify existing log records.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can pass specially crafted input to the application and modify existing log records.
Remediation
Install update from vendor's website.
References
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-sterling-b2b-integrator-vulnerable-to-security-bypass-due-to-spring-framework-cve-2021-22060/"
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-sterling-b2b-integrator-vulnerable-to-security-bypass-due-to-spring-framework-cve-2021-22060/</a><br>
- https://www.ibm.com/support/pages/node/6829861<br><br></p>