First published: Mon Apr 18 2022(Updated: )
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 213963.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling B2B Integrator | >=6.0.0.0<6.0.3.6 | |
IBM Sterling B2B Integrator | >=6.1.0.0<6.1.1.1 | |
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows | ||
<=6.0.0.0 - 6.0.3.5 | ||
<=6.1.0.0 - 6.1.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-39033.
The severity of CVE-2021-39033 is medium.
CVE-2021-39033 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser, which could be used in further attacks against the system.
IBM Sterling B2B Integrator Standard Edition versions 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 are affected by CVE-2021-39033.
To fix CVE-2021-39033, apply the relevant patches provided by IBM. You can find the patches at the following link: http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~Other%2Bsoftware&product=ibm/Other+software/Sterling+B2B+Integrator&release=All&platform=All&function=all