PT-2021-12147 · Ibm · Ibm Sterling B2B Integrator Standard Edition
Published
2021-05-19
·
Updated
2022-05-03
·
CVE-2020-4646
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Sterling B2B Integrator Standard Edition versions 5.2.0.0 through 5.2.6.5
IBM Sterling B2B Integrator Standard Edition versions 6.0.0.0 through 6.0.3.3
IBM Sterling B2B Integrator Standard Edition versions 6.1.0.0 through 6.1.0.2
Description
The issue is related to improper authorization control, allowing an authenticated user to view pages they should not have access to.
Recommendations
For versions 5.2.0.0 through 5.2.6.5, update to a version that includes proper authorization control.
For versions 6.0.0.0 through 6.0.3.3, update to a version that includes proper authorization control.
For versions 6.1.0.0 through 6.1.0.2, update to a version that includes proper authorization control.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Sterling B2B Integrator Standard Edition