CVE-2015-5019
IBM Sterling B2B Integrator and Sterling Integrator - Authenticated Arbitrary File Read and Upload
Title source: llmDescription
IBM Sterling Integrator 5.1 before 5010004_8 and Sterling B2B Integrator 5.2 before 5020500_9 allow remote authenticated users to read or upload files by leveraging a password-change requirement.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IT11008
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21967781
Scores
EPSS
0.0095
EPSS Percentile
57.5%
Details
CWE
CWE-264
Status
published
Products (2)
ibm/sterling_b2b_integrator
5.2
ibm/sterling_integrator
5.1
Published
Nov 08, 2015
Tracked Since
Feb 18, 2026