QID 375954
QID 375954: IBM Sterling B2B Integrator Access Control Security Vulnerability
IBM Sterling B2B Integrator helps companies integrate all their complex B2B/EDI processes across their partner communities in a single gateway. IBM Sterling B2B Integrator Standard Edition could allow a local user to obtain sensitive information via Queue Watcher.
Affected Versions:
IBM Sterling B2B Integrator 5.2.0.0 - 5.2.6.5_3
IBM Sterling B2B Integrator 6.0.0.0 - 6.0.3.3
IBM Sterling B2B Integrator 6.1.0.0
QID Detection Logic:(Authenticated)
This QID checks the vulnerable version of IBM B2B installed
It could allow an authenticated user to view pages they should not have access to due to improper authorization control.
Solution
Customers are advised to apply B2B Integrator version 5.2.6.5_4 or 6.0.3.4 or 6.1.0.1 to fix this vulnerability.
More information can be found CVE-2020-4646.
Vendor References
- CVE-2020-4646 -
www.ibm.com/support/pages/node/6454169
CVEs related to QID 375954
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2020-4646 |
|