CVE-2016-5890: Medium severity ibm b2b sterling integrator vulnerability
Published Nov 30, 2016
·Updated
IBM Sterling B2B Integrator 5.2 before 502050014 and 5.2 06 before 50206021 allows remote authenticated users to change arbitrary passwords via unspecified vectors.
Affected Software
1 affected component
IBM Sterling B2B Integrator=5.2
Remediation
Patch Available
Event History
Nov 30, 2016
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5890?
CVE-2016-5890 is rated as moderate severity due to the potential for unauthorized password changes by authenticated users.
2
How do I fix CVE-2016-5890?
To mitigate CVE-2016-5890, upgrade to IBM Sterling B2B Integrator version 5.2.0.14 or later.
3
Who is affected by CVE-2016-5890?
CVE-2016-5890 affects all installations of IBM Sterling B2B Integrator version 5.2 before 5020500_14 and 5.2 06 before 5020602_1.
4
What types of attacks may exploit CVE-2016-5890?
CVE-2016-5890 may be exploited through remote authenticated user actions allowing unauthorized password changes.
5
Is there any workaround for CVE-2016-5890 if I cannot upgrade immediately?
Currently, there are no documented workarounds for CVE-2016-5890 aside from applying the appropriate software update.