CVE-2013-2985
published 2013-07-03CVE-2013-2985: IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about…
PriorityP414medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
0.94%
56.7th percentile
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2987, CVE-2013-3020, CVE-2013-0568, CVE-2013-0475, and CVE-2013-0567.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| eglibc | eglibc | >= 0 < 2.19-0ubuntu6.9 | 2.19-0ubuntu6.9 |
| ibm | sterling_b2b_integrator | — | — |
| ibm | sterling_b2b_integrator | — | — |
| ibm | sterling_file_gateway | — | — |
| ibm | sterling_file_gateway | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m872-fpgq-gw4v: IBM Sterling B2B Integrator 5
ghsa_unreviewed·2022-05-17·CVSS 4.0
CVE-2013-3020 [MEDIUM] CWE-200 GHSA-m872-fpgq-gw4v: IBM Sterling B2B Integrator 5
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-2987, CVE-2013-0568, CVE-2013-0475, and CVE-2013-0567.
GHSA
GHSA-fhq7-ggf4-7jv5: IBM Sterling B2B Integrator 5
ghsa_unreviewed·2022-05-17·CVSS 4.0
CVE-2013-2985 [MEDIUM] CWE-200 GHSA-fhq7-ggf4-7jv5: IBM Sterling B2B Integrator 5
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2987, CVE-2013-3020, CVE-2013-0568, CVE-2013-0475, and CVE-2013-0567.
GHSA
GHSA-2cmc-76vf-3g3r: IBM Sterling B2B Integrator 5
ghsa_unreviewed·2022-05-17·CVSS 4.0
CVE-2013-2987 [MEDIUM] CWE-200 GHSA-2cmc-76vf-3g3r: IBM Sterling B2B Integrator 5
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-3020, CVE-2013-0568, CVE-2013-0475, and CVE-2013-0567.
GHSA
GHSA-rvp7-wrjj-rgvf: IBM Sterling B2B Integrator 5
ghsa_unreviewed·2022-05-05·CVSS 4.0
CVE-2013-0568 [MEDIUM] CWE-200 GHSA-rvp7-wrjj-rgvf: IBM Sterling B2B Integrator 5
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-2987, CVE-2013-3020, CVE-2013-0475, and CVE-2013-0567.
GHSA
GHSA-7578-v4gv-6jrj: IBM Sterling B2B Integrator 5
ghsa_unreviewed·2022-05-05·CVSS 4.0
CVE-2013-0475 [MEDIUM] CWE-200 GHSA-7578-v4gv-6jrj: IBM Sterling B2B Integrator 5
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-2987, CVE-2013-3020, CVE-2013-0568, and CVE-2013-0567.
GHSA
GHSA-pg3g-rgmp-8hp4: IBM Sterling B2B Integrator 5
ghsa_unreviewed·2022-05-05·CVSS 4.0
CVE-2013-0567 [MEDIUM] CWE-200 GHSA-pg3g-rgmp-8hp4: IBM Sterling B2B Integrator 5
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-2987, CVE-2013-3020, CVE-2013-0568, and CVE-2013-0475.
GHSA
GHSA-wgxc-hmmq-r3v4: IBM Sterling B2B Integrator 5
ghsa_unreviewed·2022-05-05·CVSS 4.0
CVE-2013-0463 [MEDIUM] CWE-200 GHSA-wgxc-hmmq-r3v4: IBM Sterling B2B Integrator 5
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-2985, CVE-2013-2987, CVE-2013-3020, CVE-2013-0568, CVE-2013-0475, and CVE-2013-0567.
OSV
eglibc, glibc regression
osv·2016-05-26·CVSS 2.6
CVE-2014-9761 eglibc, glibc regression
eglibc, glibc regression
USN-2985-1 fixed vulnerabilities in the GNU C Library. The fix for
CVE-2014-9761 introduced a regression which affected applications that
use the libm library but were not fully restarted after the upgrade.
This update removes the fix for CVE-2014-9761 and a future update
will be provided to address this issue.
We apologize for the inconvenience.
Original advisory details:
Martin Carpenter discovered that pt_chown in the GNU C Library did not
properly check permissions for tty files. A local attacker could use this
to gain administrative privileges or expose sensitive information.
(CVE-2013-2207, CVE-2016-2856)
Robin Hack discovered that the Name Service Switch (NSS) implementation in
the GNU C Library did not properly manage its file descriptors. An attacker
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-07-03
Published