First published: Wed Aug 02 2017(Updated: )
XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling File Gateway 2.1 and 2.2 allows remote attackers to read arbitrary files via a crafted XML data.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM B2B Sterling Integrator | =5.1 | |
IBM B2B Sterling Integrator | =5.2 | |
IBM Sterling File Gateway | =2.1 | |
IBM Sterling File Gateway | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0194 is classified as a medium severity vulnerability that allows remote attackers to exploit an XML External Entity (XXE) issue.
To fix CVE-2015-0194, you should upgrade to the latest versions of IBM Sterling B2B Integrator or IBM Sterling File Gateway that have addressed this vulnerability.
CVE-2015-0194 affects IBM Sterling B2B Integrator versions 5.1 and 5.2, as well as IBM Sterling File Gateway versions 2.1 and 2.2.
CVE-2015-0194 enables attackers to read arbitrary files on the server through crafted XML data.
CVE-2015-0194 can be exploited without authentication, making it a higher risk for unprotected systems.