Security Bulletin: B2B API of IBM Sterling B2B Integrator vulnerable to multiple issues due to CKEditor

## Summary IBM Sterling B2B Integrator has addressed the CKEditor security vulnerabilities in B2B API. ## Vulnerability Details ** CVEID: **[CVE-2021-32808]() ** DESCRIPTION: **CKEditor is vulnerable ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Security Bulletin: B2B API of IBM Sterling B2B Integrator vulnerable to security bypass due to OWASP ESAPI (CVE-2013-5960)

## Summary IBM Sterling B2B Integrator has addressed the vulnerability in OWASP ESAPI in B2B API ## Vulnerability Details ** CVEID: **[CVE-2013-5960]() ** DESCRIPTION: **OWASP ESAPI could allow a remo ...

Continue Reading

CVSS2 - MEDIUM

Security Bulletin: B2B API of IBM Sterling B2B Integrator is vulnerable to information disclosure (CVE-2022-22337)

## Summary IBM Sterling B2B Integrator has addressed the information disclousre vulnerability in B2B API ## Vulnerability Details ** CVEID: **[CVE-2022-22337]() ** DESCRIPTION: **IBM Sterling B2B Inte ...

Continue Reading
Security Bulletin: B2B API of IBM Sterling B2B Integrator is vulnerable to Cross Origin Resource Sharing (CORS) (CVE-2021-38928)

## Summary IBM Sterling B2B Integrator has addressed the Cross Origin Sharing vulnerability in B2B API ## Vulnerability Details ** CVEID: **[CVE-2021-38928]() ** DESCRIPTION: **IBM Sterling B2B Integr ...

Continue Reading
Apiman has potential permissions bypass

### Impact Incorrect default permissions for certain read-only resources in the Apiman 1.5.7.Final through 2.2.3.Final in the Apiman Manager REST API allows a remote authenticated attacker to access i ...

Continue Reading

CVSS3 - MEDIUM

Apiman has potential permissions bypass

### Impact Incorrect default permissions for certain read-only resources in the Apiman 1.5.7.Final through 2.2.3.Final in the Apiman Manager REST API allows a remote authenticated attacker to access i ...

Continue Reading

CVSS3 - MEDIUM

Mongoose Page Plugin < 1.9.0 – Contributor+ Stored XSS via Shortcode

The plugin does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack. ### PoC The PoC will b ...

Continue Reading
CVE-2022-39041

aEnrich a+HRD has insufficient user input validation for specific API parameter. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify an ...

Continue Reading

CVSS3 - CRITICAL

Back to Main

Subscribe for the latest news: