First published: Tue Jun 25 2019(Updated: )
IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 reveals sensitive information from a stack trace that could be used in further attacks against the system. IBM X-Force ID: 162803.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM B2B Sterling Integrator | >=5.2.0.0<=6.0.0.1 | |
HPE HP-UX | ||
IBM AIX | ||
IBM iSeries AS/400 | ||
Linux Kernel | ||
Microsoft Windows Operating System | ||
Oracle Solaris and Zettabyte File System (ZFS) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-4377 is classified as high due to the potential exposure of sensitive information from a stack trace.
To fix CVE-2019-4377, update IBM Sterling B2B Integrator to a version later than 6.0.0.1.
CVE-2019-4377 specifically affects IBM Sterling B2B Integrator versions 6.0.0.0 and 6.0.0.1.
CVE-2019-4377 is classified as an information disclosure vulnerability that may lead to further attacks.
CVE-2019-4377 was disclosed as part of ongoing security research by IBM X-Force.