CVE-2017-1349Sensitive Information Exposure in IBM Sterling B2B Integrator

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 82.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 23
Latest updateMay 17

Description

IBM Sterling B2B Integrator Standard Edition 5.2 stores potentially sensitive information from HTTP sessions that could be read by a local user. IBM X-Force ID: 126525.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wv2f-3qhc-v627: IBM Sterling B2B Integrator Standard Edition 52022-05-17
CVEList
CVE-2017-1349: IBM Sterling B2B Integrator Standard Edition 52017-06-23

💥Exploits & PoCs

1
Exploit-DB
WebKit - 'WebCore::SimpleLineLayout::RunResolver::runForPoint' Out-of-Bounds Read2017-11-22
CVE-2017-1349 — Sensitive Information Exposure in IBM | cvebase