← Vulnerability feed

Vulnerability record · CVE-2023-38739 · published 31 January 2025

CVE-2023-38739: Ibm sterling b2b integrator cross-site request forgery vulnerability

Ibm · Sterling B2b Integrator

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

8.8 CVSS 3.1 High EPSS 0.17% · top 94.6% CWE-352 · Cross-site request forgery
8.8CVSS 3.1 base score
0.17%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-38739 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2015-7450IBM products Java deserialization RCE via Commons CollectionsMultiple IBM analytics, business, IT infrastructure, and mobile/social products expose serialized-object interfaces that deserialize untrusted Java o…KEVEPSS 98%analysed9.8CVE-2023-50316Ibm sterling b2b integrator sql injection vulnerabilityIBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 is vulnerable to SQL injection. A remote attacker could send speciall…EPSS 0.35%9.8CVE-2022-22338Ibm sterling b2b integrator sql injection vulnerabilityIBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted S…EPSS 0.68%9.8CVE-2021-39085Ibm sterling b2b integrator sql injection vulnerabilityIBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to SQL injec…EPSS 0.92%9.8CVE-2021-29798Ibm sterling b2b integrator sql injection vulnerabilityIBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted S…EPSS 1.1%9.8CVE-2021-29903Ibm sterling b2b integrator sql injection vulnerabilityIBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted S…EPSS 1.1%9.3CVE-2012-5937Ibm gentran integration suite vulnerabilityUnspecified vulnerability in the CLA2 server in IBM Gentran Integration Suite 4.3, Sterling Integrator 5.0 and 5.1, and Sterling B2B Integrator 5.2, …EPSS 2.6%8.8CVE-2024-31903Ibm sterling b2b integrator deserialization of untrusted data vulnerabilityIBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 allow an attacker on the local network to execute ar…EPSS 0.97%

Source: NIST National Vulnerability Database (record CVE-2023-38739), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.