Lucene search

K
cveIbmCVE-2018-1800
HistorySep 20, 2018 - 3:29 p.m.

CVE-2018-1800

2018-09-2015:29:00
CWE-200
ibm
web.nvd.nist.gov
19
ibm
sterling b2b integrator
standard edition
vulnerability
information disclosure
local user
security

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.1

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

AI Score

4.3

Confidence

High

EPSS

0

Percentile

5.1%

IBM Sterling B2B Integrator Standard Edition 5.2.6.0 and 6.2.6.1 could allow a local user to obtain highly sensitive information during a short time period when installation is occurring. IBM X-Force ID: 149607.

Affected configurations

Nvd
Vulners
Node
ibmsterling_b2b_integratorRange5.2.6.05.2.6.3
OR
ibmsterling_b2b_integratorMatch6.2.6.1
VendorProductVersionCPE
ibmsterling_b2b_integrator*cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:*:*:*:*
ibmsterling_b2b_integrator6.2.6.1cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.6.1:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Sterling B2B Integrator",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "5.2.6.3"
      },
      {
        "status": "affected",
        "version": "5.2.6.0"
      }
    ]
  }
]

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.1

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

AI Score

4.3

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2018-1800