b2bi vulnerable to security bypass due to spring security

Integration News

B2B Integrator vulnerable to security bypass due to Spring Security

Vulnerability Details

CVEID: CVE-2022-31692
Description: VMware Tanzu Spring Security could allow a remote attacker to bypass security restrictions, caused by a flaw when using forward or include dispatcher types. By sending a specially-crafted request, an attacker could exploit this
vulnerability to bypass authorization rules.
CVSS Base score: 7.5
CVSS Temporal Score: Click here.
CVSS Vector: (CVSS:3.0/AV:/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)

CVEID: CVE-2022-22978
Description: Spring Security could allow a remote attacker to bypass security restrictions, caused by a flaw
in the RegexRequestMatcher component. By misconfiguring RegexRequestMatcher with `.` in the regular expression, an attacker could exploit this vulnerability to bypass authorization and obtain access.
CVSS Base score: 8.2
CVSS Temporal Score: Click here.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N)

Affected Products and Versions


Workarounds and Mitigations


The IIM versions of and are available on: Fix Central.

The container version of is available in IBM Entitled Registry with following tags:

  • icr.io/cp/ibm-b2bi/b2bi: for IBM Sterling B2B Integrator
  • icr.io/cp/ibm-sfg/sfg: for IBM Sterling File Gateway

Fare clic sul pulsante sottostante per scaricare questa newsletter in formato Pdf.