{"api_version":"1","generated_at":"2026-07-24T23:23:06+00:00","cve":"CVE-2013-0539","urls":{"html":"https://cve.report/CVE-2013-0539","api":"https://cve.report/api/cve/CVE-2013-0539.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-0539","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-0539"},"summary":{"title":"CVE-2013-0539","description":"An unspecified third-party component in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 uses short session ID values, which makes it easier for remote attackers to hijack sessions, and consequently obtain sensitive information, via a brute-force attack.","state":"PUBLISHED","assigner":"ibm","published_at":"2013-07-03 13:54:31","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-255","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/82916","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/82916","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21640830","name":"http://www-01.ibm.com/support/docview.wss?uid=swg21640830","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM Security Bulletin: Vulnerabilities in IBM Sterling B2B Integrator and IBM Sterling File Gateway - United States","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC92007","name":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC92007","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM IC92007: SECURITY VULNERABILITY: SESSION ID LENGTH LESS THAN 128 BIT Insufficient Session-ID Length (CVE-2013-0539)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-0539","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-0539","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"sterling_b2b_integrator","cpe6":"5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"sterling_b2b_integrator","cpe6":"5.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"sterling_file_gateway","cpe6":"2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"sterling_file_gateway","cpe6":"2.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T14:33:03.547Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21640830"},{"name":"sterling-b2b-cve20130539-sessionid(82916)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/82916"},{"name":"IC92007","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC92007"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2013-07-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"An unspecified third-party component in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 uses short session ID values, which makes it easier for remote attackers to hijack sessions, and consequently obtain sensitive information, via a brute-force attack."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21640830"},{"name":"sterling-b2b-cve20130539-sessionid(82916)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/82916"},{"name":"IC92007","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC92007"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","ID":"CVE-2013-0539","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An unspecified third-party component in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 uses short session ID values, which makes it easier for remote attackers to hijack sessions, and consequently obtain sensitive information, via a brute-force attack."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg21640830","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21640830"},{"name":"sterling-b2b-cve20130539-sessionid(82916)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/82916"},{"name":"IC92007","refsource":"AIXAPAR","url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC92007"}]}}}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2013-0539","datePublished":"2013-07-03T10:00:00.000Z","dateReserved":"2012-12-16T00:00:00.000Z","dateUpdated":"2024-08-06T14:33:03.547Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2013-07-03 13:54:31","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-255","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:sterling_b2b_integrator:5.1:*:*:*:*:*:*:*","matchCriteriaId":"40363692-5283-4D0C-BAE1-C049C02A0294"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:sterling_b2b_integrator:5.2:*:*:*:*:*:*:*","matchCriteriaId":"F805BA3A-178D-416E-9DED-4258F71A17C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:sterling_file_gateway:2.1:*:*:*:*:*:*:*","matchCriteriaId":"9A40AC14-AC2B-4A0D-A9CC-3A00B48D8975"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:sterling_file_gateway:2.2:*:*:*:*:*:*:*","matchCriteriaId":"1554D69E-D68E-46CA-B1F7-C24CAABF58E8"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"539","Ordinal":"1","Title":"CVE-2013-0539","CVE":"CVE-2013-0539","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"539","Ordinal":"1","NoteData":"An unspecified third-party component in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 uses short session ID values, which makes it easier for remote attackers to hijack sessions, and consequently obtain sensitive information, via a brute-force attack.","Type":"Description","Title":"CVE-2013-0539"},{"CveYear":"2013","CveId":"539","Ordinal":"2","NoteData":"2013-07-03","Type":"Other","Title":"Published"},{"CveYear":"2013","CveId":"539","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}