{"api_version":"1","generated_at":"2026-07-23T10:25:54+00:00","cve":"CVE-2019-4063","urls":{"html":"https://cve.report/CVE-2019-4063","api":"https://cve.report/api/cve/CVE-2019-4063.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-4063","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-4063"},"summary":{"title":"CVE-2019-4063","description":"IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 Standard Edition could allow highly sensitive information to be transmitted in plain text. An attacker could obtain this information using man in the middle techniques. IBM X-ForceID: 157008.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2019-03-05 18:29:00","updated_at":"2023-02-03 18:57:00"},"problem_types":["CWE-319"],"metrics":[],"references":[{"url":"https://www.ibm.com/support/docview.wss?uid=ibm10874234","name":"https://www.ibm.com/support/docview.wss?uid=ibm10874234","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"Security Bulletin:  Information Disclosure Security Vulnerability Affects IBM Sterling B2B Integrator (CVE-2019-4063)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/157008","name":"ibm-sterling-cve20194063-info-disc(157008)","refsource":"XF","tags":["VDB Entry","Vendor Advisory"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/107310","name":"107310","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"IBM Sterling B2B Integrator CVE-2019-4063 Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-4063","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-4063","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"4063","vulnerable":"1","versionEndIncluding":"6.0.0.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"sterling_b2b_integrator","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","DATE_PUBLIC":"2019-02-28T00:00:00","ID":"CVE-2019-4063","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Sterling B2B Integrator","version":{"version_data":[{"version_value":"5.2.0.1"},{"version_value":"6.0.0.0"}]}}]},"vendor_name":"IBM"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 Standard Edition could allow highly sensitive information to be transmitted in plain text. An attacker could obtain this information using man in the middle techniques. IBM X-ForceID: 157008."}]},"impact":{"cvssv3":{"BM":{"A":"N","AC":"H","AV":"N","C":"H","I":"N","PR":"N","S":"U","SCORE":"5.900","UI":"N"},"TM":{"E":"U","RC":"C","RL":"O"}}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Obtain Information"}]}]},"references":{"reference_data":[{"name":"ibm-sterling-cve20194063-info-disc(157008)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/157008"},{"name":"107310","refsource":"BID","url":"http://www.securityfocus.com/bid/107310"},{"name":"https://www.ibm.com/support/docview.wss?uid=ibm10874234","refsource":"CONFIRM","url":"https://www.ibm.com/support/docview.wss?uid=ibm10874234"}]}},"nvd":{"publishedDate":"2019-03-05 18:29:00","lastModifiedDate":"2023-02-03 18:57:00","problem_types":["CWE-319"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.2,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2.0.1","versionEndIncluding":"6.0.0.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"4063","Ordinal":"141674","Title":"CVE-2019-4063","CVE":"CVE-2019-4063","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"4063","Ordinal":"1","NoteData":"IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 Standard Edition could allow highly sensitive information to be transmitted in plain text. An attacker could obtain this information using man in the middle techniques. IBM X-ForceID: 157008.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"4063","Ordinal":"2","NoteData":"2019-03-05","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"4063","Ordinal":"3","NoteData":"2019-03-08","Type":"Other","Title":"Modified"}]}}}