First published: Wed Jul 03 2013(Updated: )
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not properly restrict file types and extensions, which allows remote authenticated users to bypass intended access restrictions via a crafted filename.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM B2B Sterling Integrator | =5.1 | |
IBM B2B Sterling Integrator | =5.2 | |
IBM Sterling File Gateway | =2.1 | |
IBM Sterling File Gateway | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0479 has a medium severity rating due to issues with file type restrictions.
To fix CVE-2013-0479, update to the latest versions of IBM Sterling B2B Integrator or Sterling File Gateway that address this vulnerability.
CVE-2013-0479 affects IBM Sterling B2B Integrator versions 5.1 and 5.2, and Sterling File Gateway versions 2.1 and 2.2.
The impact of CVE-2013-0479 allows remote authenticated users to bypass intended access restrictions via crafted filenames.
There is no official workaround for CVE-2013-0479, so applying the available updates is the recommended action.