First published: Sat May 15 2021(Updated: )
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5, 6.0.0.0 through 6.0.3.3, and 6.1.0.0 through 6.1.0.2 could allow an authenticated user to view pages they shoiuld not have access to due to improper authorization control.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM B2B Sterling Integrator | <=5.2.0.0 - 5.2.6.5_3 | |
IBM B2B Sterling Integrator | <=6.0.0.0 - 6.0.3.3 | |
IBM B2B Sterling Integrator | <=6.1.0.0 | |
IBM B2B Sterling Integrator | >=5.2.0.0<=5.2.6.5 | |
IBM B2B Sterling Integrator | >=6.0.0.0<=6.0.3.3 | |
IBM B2B Sterling Integrator | >=6.1.0.0<=6.1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4646 has been rated as a medium-severity vulnerability.
To fix CVE-2020-4646, apply the appropriate patches released by IBM for the affected versions of Sterling B2B Integrator.
CVE-2020-4646 affects versions 5.2.0.0 through 5.2.6.5, 6.0.0.0 through 6.0.3.3, and 6.1.0.0 through 6.1.0.2 of IBM Sterling B2B Integrator.
The impact of CVE-2020-4646 allows authenticated users to view unauthorized pages due to improper authorization control.
Yes, CVE-2020-4646 is considered to be potentially exploitative as it enables unauthorized access to restricted pages.