IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 could disclose sensitive information in the HTTP response using man in the middle techniques. IBM X-Force ID: 265507.
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/7160433 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/265507 | vdb entry vendor advisory |