CVE-2017-1326: Medium severity ibm b2b sterling integrator vulnerability
IBM Sterling File Gateway does not properly restrict user requests based on permission level. This allows for users to update data related to other users, by manipulating the parameters passed in the POST request. IBM X-Force ID: 126060.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1326?
CVE-2017-1326 is considered a medium severity vulnerability due to improper access control allowing unauthorized data updates.
How do I fix CVE-2017-1326?
To fix CVE-2017-1326, apply the latest security updates provided by IBM for Sterling File Gateway.
What types of systems are affected by CVE-2017-1326?
CVE-2017-1326 affects IBM Sterling B2B Integrator version 5.2.
What is the nature of the vulnerability in CVE-2017-1326?
CVE-2017-1326 allows users to update other users' data due to insufficient permission restrictions in user requests.
Can CVE-2017-1326 lead to data breaches?
Yes, CVE-2017-1326 can potentially lead to data breaches by allowing unauthorized access to sensitive information.