First published: Tue Nov 21 2023(Updated: )
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 247034.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling B2B Integrator | >=6.0.0.0<6.0.3.9 | |
IBM Sterling B2B Integrator | >=6.1.0.0<6.1.2.3 | |
<=6.0.0.0 - 6.0.3.8 | ||
<=6.1.0.0 - 6.1.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25682 is a vulnerability that allows a local user to read potentially sensitive information stored in log files in IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1.
CVE-2023-25682 could allow a local user to access potentially sensitive information stored in log files of IBM Sterling B2B Integrator.
The severity of CVE-2023-25682 is medium with a severity value of 6.2.
To fix CVE-2023-25682, update IBM Sterling B2B Integrator Standard Edition to a version that is not affected by the vulnerability.
You can find more information about CVE-2023-25682 on the IBM support page and the IBM X-Force ID 247034.