First published: Wed Feb 08 2017(Updated: )
IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to obtain sensitive information. By allowing HTTP OPTIONS method, a remote attacker could send a specially-crafted query to a vulnerable server running to cause the server to disclose sensitive information in the HTTP response.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM B2B Sterling Integrator | =5.1 | |
IBM B2B Sterling Integrator | =5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0210 is considered a medium severity vulnerability due to the potential for sensitive data exposure.
To fix CVE-2016-0210, disable the HTTP OPTIONS method on the affected IBM Sterling B2B Integrator servers.
CVE-2016-0210 affects IBM Sterling B2B Integrator versions 5.1 and 5.2.
CVE-2016-0210 involves a remote attacker exploiting the HTTP OPTIONS method to retrieve sensitive information.
The primary workaround for CVE-2016-0210 is to configure web servers to block the HTTP OPTIONS method.