First published: Wed Nov 30 2016(Updated: )
IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote authenticated users to change arbitrary passwords via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM B2B Sterling Integrator | =5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5890 is rated as moderate severity due to the potential for unauthorized password changes by authenticated users.
To mitigate CVE-2016-5890, upgrade to IBM Sterling B2B Integrator version 5.2.0.14 or later.
CVE-2016-5890 affects all installations of IBM Sterling B2B Integrator version 5.2 before 5020500_14 and 5.2 06 before 5020602_1.
CVE-2016-5890 may be exploited through remote authenticated user actions allowing unauthorized password changes.
Currently, there are no documented workarounds for CVE-2016-5890 aside from applying the appropriate software update.