PT-2025-2683 · Ibm · Ibm Sterling B2B Integrator

Published

2025-01-31

·

Updated

2025-01-31

·

CVE-2024-45089

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Sterling B2B Integrator versions 6.0.0.0 through 6.1.2.5 IBM Sterling B2B Integrator versions 6.2.0.0 through 6.2.0.3
Description The issue allows an authenticated user to obtain sensitive filename information due to an observable discrepancy in the Standard Edition EBICS server.
Recommendations For versions 6.0.0.0 through 6.1.2.5, update to a version that addresses the issue. For versions 6.2.0.0 through 6.2.0.3, update to a version that addresses the issue. As a temporary workaround, consider restricting access to the EBICS server to minimize the risk of exploitation.

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2024-45089

Affected Products

Ibm Sterling B2B Integrator