First published: Fri May 08 2020(Updated: )
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 could expose sensitive information to a user through a specially crafted HTTP request. IBM X-Force ID: 176606.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling File Gateway | >=5.2.0.0<=5.2.6.5_1 | |
IBM Sterling File Gateway | >=6.0.0.0<=6.0.3.1 | |
HP HP-UX | ||
IBM AIX | ||
IBM i | ||
Linux Linux kernel | ||
Microsoft Windows | ||
Oracle Solaris | ||
<=6.0.0.0 - 6.0.3.1 | ||
<=5.2.0.0 - 5.2.6.5_1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-4299.
CVE-2020-4299 has a severity value of 4.3 (medium).
IBM Sterling B2B Integrator Standard Edition versions 5.2.0.0 through 6.0.3.1 are affected by CVE-2020-4299.
A user can exploit CVE-2020-4299 by sending a specially crafted HTTP request.
Yes, there is a patch available to fix CVE-2020-4299. You can find more information and download the patch from the IBM Support website.