CVE-2014-6099IBM Sterling B2B Integrator vulnerability

CWE-2553 documents3 sources
Severity
5.0MEDIUMNVD
EPSS
0.3%
top 48.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 26
Latest updateMay 17

Description

The Change Password feature in IBM Sterling B2B Integrator 5.2.x through 5.2.4 does not have a lockout protection mechanism for invalid login requests, which makes it easier for remote attackers to obtain admin access via a brute-force approach.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDibm/sterling_b2b_integrator5.2, 5.2.4+1

🔴Vulnerability Details

2
GHSA
GHSA-m8qj-xj8r-x99h: The Change Password feature in IBM Sterling B2B Integrator 52022-05-17
CVEList
CVE-2014-6099: The Change Password feature in IBM Sterling B2B Integrator 52014-10-26
CVE-2014-6099 — IBM vulnerability | cvebase