CVE-2024-27263

Severity CVSS v4.0:
Pending analysis
Type:
CWE-300 Channel Accessible by Non-Endpoint
Publication date:
28/01/2025
Last modified:
04/03/2025

Description

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to obtain sensitive information from the dashboard UI using man in the middle techniques.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:*:*:*:* 6.0.0.0 (including) 6.1.2.5 (including)
cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:*:*:*:* 6.2.0.0 (including) 6.2.0.1 (including)


References to Advisories, Solutions, and Tools