Site icon API Security Blog

Security Bulletin: B2B API of IBM Sterling B2B Integrator is vulnerable to information disclosure due to Springfox Swagger (CVE-2019-17495)

Summary IBM Sterling B2B Integrator uses Springfox Swagger. This bulletin identifies the steps to take to address the vulnerabilities. Vulnerability Details ** CVEID: CVE-2019-17495 DESCRIPTION: **Swagger UI could allow a remote attacker to obtain sensitive information, caused by a CSS injection flaw. By using the relative path overwrite (RPO) attack technique, an attacker could exploit this vulnerability to obtain sensitive information. CVSS Base score: 5.3 CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/169050 for the current score. CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) Affected Products and Versions Affected Product(s)| Version(s) —|— IBM Sterling B2B Integrator| 6.0.0.0 – 6.0.3.9 IBM Sterling B2B Integrator| 6.1.0.0 – 6.1.2.5 Remediation/Fixes IBM strongly recommends addressing the vulnerability now. Product| Version| APAR| Remediation & Fix —|—|—|— IBM Sterling B2B Integrator| 6.0.0.0 – 6.0.3.9| IT43948| Apply B2BI 6.2.0.1 IBM Sterling B2B Integrator| 6.1.0.0 – 6.1.2.5| IT43948| Apply B2BI 6.2.0.1 The IIM versions of 6.2.0.1 is available on Fix Central. The container version of 6.2.0.1 is available in IBM Entitled Registry. Workarounds and Mitigations…Read More

Exit mobile version