First published: Sat Jan 10 2015(Updated: )
The HTTP Server Adapter in IBM Sterling B2B Integrator 5.1 and 5.2.x and Sterling File Gateway 2.1 and 2.2 allows remote attackers to cause a denial of service (connection-slot exhaustion) via a crafted HTTP request.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM B2B Sterling Integrator | =5.1 | |
IBM B2B Sterling Integrator | =5.2 | |
IBM B2B Sterling Integrator | =5.2.1 | |
IBM B2B Sterling Integrator | =5.2.2 | |
IBM B2B Sterling Integrator | =5.2.4 | |
IBM B2B Sterling Integrator | =5.2.4.1 | |
IBM B2B Sterling Integrator | =5.2.4.2 | |
IBM B2B Sterling Integrator | =5.2.5.0 | |
IBM Sterling File Gateway | =2.1 | |
IBM Sterling File Gateway | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6199 has a severity rating that indicates it could lead to denial of service due to connection-slot exhaustion.
To fix CVE-2014-6199, it is recommended to apply the latest patches provided by IBM for the affected versions of Sterling B2B Integrator and Sterling File Gateway.
CVE-2014-6199 affects IBM Sterling B2B Integrator versions 5.1, 5.2.x and Sterling File Gateway versions 2.1 and 2.2.
CVE-2014-6199 allows remote attackers to launch denial of service attacks through crafted HTTP requests.
While patches are the best solution, limiting the number of concurrent connections can act as a temporary workaround for CVE-2014-6199.