CVE-2014-6199: Medium severity ibm b2b sterling integrator vulnerability
The HTTP Server Adapter in IBM Sterling B2B Integrator 5.1 and 5.2.x and Sterling File Gateway 2.1 and 2.2 allows remote attackers to cause a denial of service (connection-slot exhaustion) via a crafted HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6199?
CVE-2014-6199 has a severity rating that indicates it could lead to denial of service due to connection-slot exhaustion.
How do I fix CVE-2014-6199?
To fix CVE-2014-6199, it is recommended to apply the latest patches provided by IBM for the affected versions of Sterling B2B Integrator and Sterling File Gateway.
Which versions are affected by CVE-2014-6199?
CVE-2014-6199 affects IBM Sterling B2B Integrator versions 5.1, 5.2.x and Sterling File Gateway versions 2.1 and 2.2.
What types of attacks does CVE-2014-6199 allow?
CVE-2014-6199 allows remote attackers to launch denial of service attacks through crafted HTTP requests.
Is there a workaround for CVE-2014-6199?
While patches are the best solution, limiting the number of concurrent connections can act as a temporary workaround for CVE-2014-6199.