First published: Mon Feb 17 2020(Updated: )
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 167878.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM B2B Sterling Integrator | <=5.2.0.0 - 6.0.3.0 | |
IBM B2B Sterling Integrator | >=5.2.0.0<=5.2.6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4595 is classified as a high severity vulnerability due to the potential for remote attackers to exploit it for phishing attacks.
To fix CVE-2019-4595, install the latest patches available from IBM for the Sterling B2B Integrator version you are using.
CVE-2019-4595 affects IBM Sterling B2B Integrator versions 5.2.0.0 through 5.2.6.5.
CVE-2019-4595 enables remote attackers to conduct phishing attacks using an open redirect mechanism.
CVE-2019-4595 cannot be exploited locally since it requires a remote attacker to convince the victim to visit a specially-crafted website.