CVE-2019-4063Cleartext Transmission of Sensitive Info in IBM Sterling B2B Integrator

Severity
5.9MEDIUMNVD
EPSS
0.1%
top 67.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 5
Latest updateMay 13

Description

IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 Standard Edition could allow highly sensitive information to be transmitted in plain text. An attacker could obtain this information using man in the middle techniques. IBM X-ForceID: 157008.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

NVDibm/sterling_b2b_integrator5.2.0.16.0.0.0
CVEListV5ibm/sterling_b2b_integrator5.2.0.1, 6.0.0.0+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-ch7w-vv63-2j88: IBM Sterling B2B Integrator 52022-05-13
CVEList
CVE-2019-4063: IBM Sterling B2B Integrator 52019-03-05
CVE-2019-4063 — IBM vulnerability | cvebase