Description
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow an authenticated user to create a privileged account due to improper access controls. IBM X-Force ID: 188896.
CVSS breakdown
CVSS 3.0
Availability
High
User Interaction
None
Privileges Required
Low
Confidentiality
High
Attack Vector
Network
Integrity
High
Scope
Unchanged
Attack Complexity
Low
E
Unchanged
RL
O
RC
Changed
Affected products
- ibm / sterling_b2b_integrator6.0.0.0 – 6.0.0.0
- ibm / sterling_b2b_integrator5.2.0.0 – 5.2.0.0
- ibm / sterling_b2b_integrator6.0.3.2 – 6.0.3.2
- ibm / sterling_b2b_integrator6.1.0.0 – 6.1.0.0
- ibm / sterling_b2b_integrator5.2.6.5_2 – 5.2.6.5_2