First published: Thu Jun 22 2017(Updated: )
IBM Sterling File Gateway does not properly restrict user requests based on permission level. This allows for users to update data related to other users, by manipulating the parameters passed in the POST request. IBM X-Force ID: 126060.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM B2B Sterling Integrator | =5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1326 is considered a medium severity vulnerability due to improper access control allowing unauthorized data updates.
To fix CVE-2017-1326, apply the latest security updates provided by IBM for Sterling File Gateway.
CVE-2017-1326 affects IBM Sterling B2B Integrator version 5.2.
CVE-2017-1326 allows users to update other users' data due to insufficient permission restrictions in user requests.
Yes, CVE-2017-1326 can potentially lead to data breaches by allowing unauthorized access to sensitive information.