First published: Sun Oct 26 2014(Updated: )
The Change Password feature in IBM Sterling B2B Integrator 5.2.x through 5.2.4 does not have a lockout protection mechanism for invalid login requests, which makes it easier for remote attackers to obtain admin access via a brute-force approach.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM B2B Sterling Integrator | =5.2 | |
IBM B2B Sterling Integrator | =5.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-6099 is high due to the lack of a lockout mechanism allowing brute-force attacks on admin access.
To fix CVE-2014-6099, implement a lockout policy on the Change Password feature to prevent repeated invalid login attempts.
CVE-2014-6099 affects users of IBM Sterling B2B Integrator versions 5.2.x up to and including 5.2.4.
An attacker can exploit CVE-2014-6099 to gain unauthorized admin access using brute-force login attempts.
CVE-2014-6099 is considered a web application vulnerability rather than a network vulnerability.