CVE-2023-25682Log File Information Exposure in IBM Sterling B2B Integrator

Severity
5.5MEDIUMNVD
CNA6.2
EPSS
0.0%
top 94.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 22

Description

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 247034.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/sterling_b2b_integrator_standard_edition6.0.0.06.0.3.8+1
NVDibm/sterling_b2b_integrator6.0.0.06.0.3.9+1

🔴Vulnerability Details

2
CVEList
IBM Sterling B2B Integrator information disclosure2023-11-22
GHSA
GHSA-phcq-62x8-mj46: IBM Sterling B2B Integrator Standard Edition 62023-11-22
CVE-2023-25682 — Log File Information Exposure in IBM | cvebase