PT-2023-20241 · Ibm · Ibm Sterling B2B Integrator Standard Edition
Published
2023-11-22
·
Updated
2023-11-30
·
CVE-2023-25682
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Sterling B2B Integrator Standard Edition versions 6.0.0.0 through 6.0.3.8
IBM Sterling B2B Integrator Standard Edition versions 6.1.0.0 through 6.1.2.1
Description
The issue allows potentially sensitive information to be stored in log files, which could be read by a local user.
Recommendations
For versions 6.0.0.0 through 6.0.3.8, update to a version that does not store sensitive information in log files.
For versions 6.1.0.0 through 6.1.2.1, update to a version that does not store sensitive information in log files.
As a temporary workaround, consider restricting access to log files to minimize the risk of exploitation.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Sterling B2B Integrator Standard Edition