QID 379511
Date Published: 2024-03-26
QID 379511: IBM Integration Bus Cross-Site Request Forgery (CSRF) Vulnerability (7140678)
CVE-2024-27265: IBM Integration Bus is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Affected Versions:
IBM Integration Bus 10.1 - 10.1.0.3
Note: Detection is potential as we cannot check for "PH60208".
QID Detection Logic (Authenticated):
Operating System: Windows
The QID checks if a vulnerable version of IBM Integration Bus by checking the registry entry.
Operating System: Linux
The QID checks if a vulnerable version of IBM Integration Bus by firing strings /opt/IIB/iib*/iib command.
Successful exploitation of this vulnerability could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
- IBM Security Bulletin (7140678) -
www.ibm.com/support/pages/node/7140678
CVEs related to QID 379511
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 7140678 |
|