CVE-2015-5019

IBM Sterling B2B Integrator and Sterling Integrator - Authenticated Arbitrary File Read and Upload

Title source: llm
STIX 2.1

Description

IBM Sterling Integrator 5.1 before 5010004_8 and Sterling B2B Integrator 5.2 before 5020500_9 allow remote authenticated users to read or upload files by leveraging a password-change requirement.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IT11008
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21967781

Scores

EPSS 0.0095
EPSS Percentile 57.5%

Details

CWE
CWE-264
Status published
Products (2)
ibm/sterling_b2b_integrator 5.2
ibm/sterling_integrator 5.1
Published Nov 08, 2015
Tracked Since Feb 18, 2026