IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.1 discloses sensitive information to an authenticated user from the dashboard UI which could be used in further attacks against the system. IBM X-Force ID: 172753.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/6380390 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/172753 | vdb entry vendor advisory |