Lucene search

K
ibmIBM140579145D648454A625A40BFB7B32C28BED8C44AED026D32BAC5B45A637A2BD
HistoryJun 16, 2018 - 7:48 p.m.

Security Bulletin: Authentication Bypass vulnerability found in IBM Sterling B2B Integrator (CVE-2015-5019)

2018-06-1619:48:17
www.ibm.com
20

EPSS

0.001

Percentile

46.5%

Summary

IBM Sterling B2B Integrator could allow a local mailbox user under specific circumstances to upload or download files without proper authorization.

Vulnerability Details

CVEID: CVE-2015-5019**
DESCRIPTION: *IBM Sterling B2B Integrator Standard Edition could allow a local mailbox user with expired or new passwords that are in of need changing to upload or download files without proper authorization controls.
CVSS Base Score: 3.6
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/106463&gt; for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N)

Affected Products and Versions

Sterling B2B Integrator 5.1

IBM Sterling B2B Integrator 5.2

Remediation/Fixes

PRODUCT & Version

|

APAR

|

Remediation/Fix

—|—|—

Sterling Integrator 5.1

|

IT11008

|

Apply Generic Interim Fix 5010004_8 available on IWM

IBM Sterling B2B Integrator 5.2

|

IT11008

|

Apply Generic Interim Fix 5020500_9 available on Fix Central

Workarounds and Mitigations

None

EPSS

0.001

Percentile

46.5%

Related for 140579145D648454A625A40BFB7B32C28BED8C44AED026D32BAC5B45A637A2BD