CVE-2014-0927
Summary
| CVE | CVE-2014-0927 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-04-20 21:29:00 UTC |
| Updated | 2018-05-22 15:17:00 UTC |
| Description | The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to bypass authentication by leveraging knowledge of the port number and webapp path. IBM X-Force ID: 92259. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Sterling B2b Integrator | 5.1 | All | All | All |
| Application | Ibm | Sterling B2b Integrator | 5.2 | All | All | All |
| Application | Ibm | Sterling B2b Integrator | 5.1 | All | All | All |
| Application | Ibm | Sterling B2b Integrator | 5.2 | All | All | All |
| Application | Ibm | Sterling File Gateway | 2.1 | All | All | All |
| Application | Ibm | Sterling File Gateway | 2.2 | All | All | All |
| Application | Ibm | Sterling File Gateway | 2.1 | All | All | All |
| Application | Ibm | Sterling File Gateway | 2.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | VDB Entry, Vendor Advisory |
| Security Bulletin: Vulnerabilities found in IBM Sterling B2B Integrator and IBM Sterling File Gateway (CVE-2014-0114, CVE-2014-0927, CVE-2014-0912) | CONFIRM | www-01.ibm.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.