CVE-2020-4671
published 2020-11-16CVE-2020-4671: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 stores potentially sensitive information in log files that…
PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.03%
59.9th percentile
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 stores potentially sensitive information in log files that could be read by an authenticatedl user. IBM X-Force ID: 186284.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | sterling_b2b_integrator | — | — |
| ibm | sterling_b2b_integrator | — | — |
| ibm | sterling_b2b_integrator | — | — |
| ibm | sterling_b2b_integrator | — | — |
| ibm | sterling_b2b_integrator | 5.2.0.0 – 5.2.6.5 | — |
| ibm | sterling_b2b_integrator | 6.0.0.0 – 6.0.3.2 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SERVER Adobe Flash Player Rosetta Flash compressed CWS in URI
suricata·2014-07-18
CVE-2014-4671 ET WEB_SERVER Adobe Flash Player Rosetta Flash compressed CWS in URI
ET WEB_SERVER Adobe Flash Player Rosetta Flash compressed CWS in URI
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER Adobe Flash Player Rosetta Flash compressed CWS in URI"; flow:established,to_server; urilen:>70; http.uri; content:"callback=CWS"; nocase; pcre:"/^[a-z0-9\.\_]{5}hC[a-z0-9\.\_]{50}/Ri"; reference:url,miki.it/blog/2014/7/8/abusing-jsonp-with-rosetta-flash/; reference:cve,2014-4671; classtype:attempted-user; sid:2018740; rev:3; metadata:created_at 2014_07_18, cve CVE_2014_4671, signature_severity Minor, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_04_30;)
No public exploits indexed.
No writeups or analysis indexed.
2020-11-16
Published