VulnerabilityModified
CVE-2017-1131
IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information by using unsupported, specially crafted HTTP commands.
MEDIUM 6.5EPSS 1.44%
Does this matter?
Lower severity and a low EPSS score (1.44%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information by using unsupported, specially crafted HTTP commands. IBM X-Force ID: 121375.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.44% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/sterling b2b integrator
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=swg22004270Patch, Vendor Advisory
- http://www.securityfocus.com/bid/99227
- https://exchange.xforce.ibmcloud.com/vulnerabilities/121375VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22004270Patch, Vendor Advisory
- http://www.securityfocus.com/bid/99227
- https://exchange.xforce.ibmcloud.com/vulnerabilities/121375VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.