First published: Fri Nov 13 2020(Updated: )
IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2 stores potentially highly sensitive information in log files that could be read by an authenticated user. IBM X-Force ID: 184083.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling B2B Integrator | >=5.2.6.0<=5.2.6.5 | |
IBM Sterling B2B Integrator | >=6.0.0.0<=6.0.3.2 | |
IBM B2B API in IBM Sterling B2B Integrator | <=6.0.0.0 - 6.0.3.2 | |
IBM B2B API in IBM Sterling B2B Integrator | <=5.2.6.0 - 5.2.6.5_2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4566 is a vulnerability in IBM Sterling B2B Integrator Standard Edition that allows an authenticated user to read potentially highly sensitive information stored in log files.
IBM Sterling B2B Integrator versions 5.2.6.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2 are affected by CVE-2020-4566.
CVE-2020-4566 has a severity level of 6.5, which is considered medium.
An authenticated user can exploit CVE-2020-4566 by reading sensitive information stored in log files.
Yes, IBM has released a patch for CVE-2020-4566. You can find the patch at the following URL: [URL](http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~Other%2Bsoftware&product=ibm/Other+software/Sterling+B2B+Integrator&release=All&platform=All&function=all)