PT-2017-6434 · Ibm · Ibm Sterling File Gateway+1

Published

2017-08-02

·

Updated

2017-08-14

·

CVE-2015-0194

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Sterling B2B Integrator versions 5.1 through 5.2 IBM Sterling File Gateway versions 2.1 through 2.2
Description The issue allows remote attackers to read arbitrary files via a crafted XML data, exploiting an XML External Entity (XXE) vulnerability.
Recommendations For IBM Sterling B2B Integrator versions 5.1 through 5.2, update to a version that includes a fix for this issue. For IBM Sterling File Gateway versions 2.1 through 2.2, update to a version that includes a fix for this issue.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-0194

Affected Products

Ibm Sterling B2B Integrator
Ibm Sterling File Gateway