PT-2016-3763 · Ibm · Ibm Sterling B2B Integrator
Published
2016-01-01
·
Updated
2016-11-28
·
CVE-2015-7410
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Sterling B2B Integrator version 5.2
Description
The issue concerns the Health Check tool in IBM Sterling B2B Integrator, which does not properly utilize cookies in conjunction with HTTPS sessions. This allows man-in-the-middle attackers to obtain sensitive information or modify data.
Recommendations
For IBM Sterling B2B Integrator version 5.2, consider disabling the Health Check tool until a patch is available to prevent potential exploitation. Restrict access to sensitive information and ensure that all sessions are properly secured to minimize the risk of data modification by unauthorized parties.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Sterling B2B Integrator