CVE-2014-6146: Infoleak
Published Nov 8, 2014
·Updated
IBM Sterling B2B Integrator 5.2.x through 5.2.4, when the Connect:Direct Server Adapter is configured, does not properly process the logging configuration, which allows local users to obtain sensitive information by reading log files.
Affected Software
3 affected components
IBM Sterling B2B Integrator=5.2.1
IBM Sterling B2B Integrator=5.2.2
IBM Sterling B2B Integrator=5.2.4
Event History
Nov 8, 2014
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6146?
CVE-2014-6146 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2014-6146?
To fix CVE-2014-6146, ensure that logging configurations are properly secured and limit access to log files.
3
Who is affected by CVE-2014-6146?
CVE-2014-6146 affects local users of IBM Sterling B2B Integrator versions 5.2.1 through 5.2.4.
4
What information can be exposed due to CVE-2014-6146?
CVE-2014-6146 can allow local users to obtain sensitive information contained within the log files.
5
Is there a workaround for CVE-2014-6146?
A potential workaround for CVE-2014-6146 involves restricting access permissions to the log files.