First published: Tue Jul 16 2024(Updated: )
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 could disclose sensitive information in the HTTP response using man in the middle techniques. IBM X-Force ID: 265507.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling B2B Integrator | <=6.2.0.0 - 6.2.0.2 | |
IBM Sterling B2B Integrator | <=6.0.0.0 - 6.1.2.5 | |
IBM Sterling B2B Integrator | >=6.0.0.0<=6.1.2.5 | |
IBM Sterling B2B Integrator | >=6.2.0.0<=6.2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-42010 is considered to have a moderate severity level due to the potential disclosure of sensitive information.
To fix CVE-2023-42010, update IBM Sterling B2B Integrator to a version above 6.2.0.2 or 6.1.2.5.
CVE-2023-42010 affects IBM Sterling B2B Integrator versions from 6.0.0.0 to 6.1.2.5 and 6.2.0.0 to 6.2.0.2.
CVE-2023-42010 exploits man-in-the-middle techniques to disclose sensitive information in the HTTP response.
There are no known workarounds for CVE-2023-42010; updating to a patched version is recommended.