CVE-2020-4299: Medium severity IBM Sterling B2B Integrator vulnerability
Published May 8, 2020
·Updated
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 could expose sensitive information to a user through a specially crafted HTTP request. IBM X-Force ID: 176606.
Other sources
IBM Sterling B2B Integrator Standard Edition could expose sensitive information to a user through a specially crafted HTTP request.
— IBM
Affected Software
10 affected componentsFixes available
IBM Sterling B2B Integrator<=6.0.0.0 - 6.0.3.1
IBM Sterling B2B Integrator<=5.2.0.0 - 5.2.6.5_1
IBM Sterling File Gateway>=5.2.0.0<=5.2.6.5_1
IBM Sterling File Gateway>=6.0.0.0<=6.0.3.1
HP HP-UX
IBM AIX
IBM i
Linux Linux kernel
Microsoft Windows
Oracle Solaris
Event History
May 8, 2020
CVE Published
via IBM·12:00 AM
May 14, 2020
CVE Published
via MITRE·03:50 PM
Data Sourced
via MITRE·03:50 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-4299.
2
What is the severity of CVE-2020-4299?
CVE-2020-4299 has a severity value of 4.3 (medium).
3
Which software versions are affected by CVE-2020-4299?
IBM Sterling B2B Integrator Standard Edition versions 5.2.0.0 through 6.0.3.1 are affected by CVE-2020-4299.
4
How can a user exploit this vulnerability?
A user can exploit CVE-2020-4299 by sending a specially crafted HTTP request.
5
Is there a patch available to fix this vulnerability?
Yes, there is a patch available to fix CVE-2020-4299. You can find more information and download the patch from the IBM Support website.