CVE-2015-7410: High severity ibm b2b sterling integrator vulnerability
Published Jan 1, 2016
·Updated
The Health Check tool in IBM Sterling B2B Integrator 5.2 does not properly use cookies in conjunction with HTTPS sessions, which allows man-in-the-middle attackers to obtain sensitive information or modify data via unspecified vectors.
Affected Software
1 affected component
IBM Sterling B2B Integrator=5.2
Event History
Jan 1, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7410?
CVE-2015-7410 is classified as a medium severity vulnerability.
2
How does CVE-2015-7410 affect IBM Sterling B2B Integrator 5.2?
CVE-2015-7410 allows man-in-the-middle attackers to obtain sensitive information or modify data due to improper cookie handling in HTTPS sessions.
3
What types of attacks are possible due to CVE-2015-7410?
CVE-2015-7410 can lead to man-in-the-middle attacks that compromise sensitive information.
4
How do I fix CVE-2015-7410?
To fix CVE-2015-7410, ensure that cookie settings are properly configured for secure HTTPS usage.
5
Is CVE-2015-7410 present in versions of IBM Sterling B2B Integrator other than 5.2?
CVE-2015-7410 specifically affects IBM Sterling B2B Integrator version 5.2.