CVE-2017-1193Sensitive Information Exposure in IBM Sterling B2B Integrator

Severity
6.5MEDIUMNVD
EPSS
0.3%
top 48.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 23
Latest updateMay 17

Description

IBM Sterling B2B Integrator Standard Edition 5.2 could allow user to obtain sensitive information using an HTTP GET request. IBM X-Force ID: 123667.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mq4v-4859-39pp: IBM Sterling B2B Integrator Standard Edition 52022-05-17
CVEList
CVE-2017-1193: IBM Sterling B2B Integrator Standard Edition 52017-06-23

💥Exploits & PoCs

1
Exploit-DB
Microsoft Windows - 'nt!NtQueryInformationJobObject (information class 12)' Kernel Stack Memory Disclosure2017-06-22
CVE-2017-1193 — Sensitive Information Exposure in IBM | cvebase