First published: Fri Jul 20 2018(Updated: )
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) caches usernames and passwords in browsers that could be used by a local attacker to obtain sensitive information. IBM X-Force ID: 130812.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling File Gateway | >=2.2.0<=2.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2017-1544.
The severity of CVE-2017-1544 is high.
CVE-2017-1544 allows a local attacker to obtain sensitive information by exploiting the caching of usernames and passwords in browsers.
To fix CVE-2017-1544 in IBM Sterling File Gateway, update to a version higher than 2.2.6 or apply the necessary patches.
You can find more information about CVE-2017-1544 on the IBM support website, SecurityFocus, and IBM X-Force Exchange.