Lucene search

K
ibmIBMBDDECF3AE3E7E0085024BCB8FDC39745C48AA75E4DF31065653CF854B592650B
HistoryNov 21, 2023 - 4:31 p.m.

Security Bulletin: IBM Sterling B2B Integrator is vulnerable to information disclosure (CVE-2023-25682)

2023-11-2116:31:24
www.ibm.com
9
ibm sterling b2b integrator
information disclosure
vulnerability
addressed
log files
local user
sensitive information
cvss score
affected products
versions
remediation
fixes
iim version
container version

6.2 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

6.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Summary

An information disclosure security vulnerabilty has been addressed in IBM Sterling B2B Integrator.

Vulnerability Details

CVEID:CVE-2023-25682
**DESCRIPTION:**IBM Sterling B2B Integrator Standard Edition stores potentially sensitive information in log files that could be read by a local user.
CVSS Base score: 6.2
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/247034 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Sterling B2B Integrator 6.0.0.0 - 6.0.3.8
IBM Sterling B2B Integrator 6.1.0.0 - 6.1.2.1

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now.

Product Version APAR Remediation & Fix
IBM Sterling B2B Integrator 6.0.0.0 - 6.0.3.8 IT42985 Apply 6.0.3.9
IBM Sterling B2B Integrator 6.1.0.0 - 6.1.2.1 IT42985 Apply 6.1.2.3 or 6.2.0.0

The IIM versions of 6.0.3.9 and 6.1.2.3 are available on Fix Central. The IIM version of 6.2.0.0 is available on Passport Advantage

The container version of 6.1.2.3 and 6.2.0.0 are available in IBM Entitled Registry.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmsterling_b2b_integratorMatch6.0.0.0
OR
ibmsterling_b2b_integratorMatch6.2.0.0

6.2 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

6.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for BDDECF3AE3E7E0085024BCB8FDC39745C48AA75E4DF31065653CF854B592650B