IBM Sterling B2B Integrator 5.2.x through 5.2.4, when the Connect:Direct Server Adapter is configured, does not properly process the logging configuration, which allows local users to obtain sensitive information by reading log files.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://secunia.com/advisories/62190 | third party advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg21689082 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1IT04337 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/96916 | vdb entry |