PT-2014-7044 · Ibm · Ibm Sterling B2B Integrator
Published
2014-10-26
·
Updated
2017-09-08
·
CVE-2014-6099
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Sterling B2B Integrator versions 5.2.x through 5.2.4
Description
The issue concerns the Change Password feature, which lacks a lockout protection mechanism for invalid login requests. This makes it easier for remote attackers to gain admin access using a brute-force approach.
Recommendations
For IBM Sterling B2B Integrator versions 5.2.x through 5.2.4, consider implementing a custom lockout mechanism to limit invalid login attempts as a temporary workaround until a patch is available. Restrict access to the Change Password feature to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Sterling B2B Integrator