CVE-2023-42010

LOW

IBM Sterling B2B Integrator <6.1.2.5, <6.2.0.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 could disclose sensitive information in the HTTP response using man in the middle techniques. IBM X-Force ID: 265507.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
https://www.ibm.com/support/pages/node/7160433

Scores

CVSS v3 3.1
EPSS 0.0031
EPSS Percentile 22.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-497
Status published
Products (1)
ibm/sterling_b2b_integrator 6.0.0.0 - 6.1.2.5
Published Jul 17, 2024
Tracked Since Feb 18, 2026