CVE-2023-42010

July 17, 2024, 6:15 p.m.

Received
CVE has been recently published to the CVE List and has been received by the NVD.

Products

IBM Sterling B2B Integrator Standard Edition

  • 6.0.0.0 - 6.1.2.5
  • 6.2.0.0 - 6.2.0.2

Source

psirt@us.ibm.com

Tags

CVE-2023-42010 details

Published : July 17, 2024, 6:15 p.m.
Last Modified : July 17, 2024, 6:15 p.m.

Description

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 could disclose sensitive information in the HTTP response using man in the middle techniques. IBM X-Force ID: 265507.

CVSS Score

1 2 3.1 4 5 6 7 8 9 10

Weakness

Weakness Name Description
CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

CVSS Data

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

Base Score

3.1

Exploitability Score

1.6

Impact Score

1.4

Base Severity

LOW

This website uses the NVD API, but is not approved or certified by it.