PT-2014-7044 · Ibm · Ibm Sterling B2B Integrator

Published

2014-10-26

·

Updated

2017-09-08

·

CVE-2014-6099

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM Sterling B2B Integrator versions 5.2.x through 5.2.4
Description The issue concerns the Change Password feature, which lacks a lockout protection mechanism for invalid login requests. This makes it easier for remote attackers to gain admin access using a brute-force approach.
Recommendations For IBM Sterling B2B Integrator versions 5.2.x through 5.2.4, consider implementing a custom lockout mechanism to limit invalid login attempts as a temporary workaround until a patch is available. Restrict access to the Change Password feature to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-6099

Affected Products

Ibm Sterling B2B Integrator