PT-2016-3763 · Ibm · Ibm Sterling B2B Integrator
Publicado
2016-01-01
·
Atualizado
2016-11-28
·
CVE-2015-7410
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Sterling B2B Integrator version 5.2
Description
The issue concerns the Health Check tool in IBM Sterling B2B Integrator, which does not properly utilize cookies in conjunction with HTTPS sessions. This allows man-in-the-middle attackers to obtain sensitive information or modify data.
Recommendations
For IBM Sterling B2B Integrator version 5.2, consider disabling the Health Check tool until a patch is available to prevent potential exploitation. Restrict access to sensitive information and ensure that all sessions are properly secured to minimize the risk of data modification by unauthorized parties.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Sterling B2B Integrator