Cross-site request forgery in IBM Sterling File Gateway and IBM Sterling B2B Integrator - CVE-2024-54172

 

Cross-site request forgery in IBM Sterling File Gateway and IBM Sterling B2B Integrator - CVE-2024-54172

Published: June 18, 2025


Vulnerability identifier: #VU111278
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-54172
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform cross-site request forgery attacks.

The vulnerability exists due to insufficient validation of the HTTP request origin. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website.


Affected software

IBM Sterling File Gateway
IBM Sterling B2B Integrator

How to mitigate CVE-2024-54172

Install updates from vendor's website.

IBM Sterling File Gateway - addressed in versions 6.1.2.7, 6.2.0.5, 6.2.1.0
IBM Sterling B2B Integrator - addressed in versions 6.1.2.7, 6.2.0.5, 6.2.1.0

External References

Related Security Bulletins