- EPSS 93.49%
- Veröffentlicht 02.01.2016 21:59:15
- Zuletzt bearbeitet 22.10.2025 00:15:45
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerT...
CVE-2015-7438
- EPSS 0.04%
- Veröffentlicht 02.01.2016 21:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
IBM Sterling B2B Integrator 5.2 allows local users to obtain sensitive cleartext web-services information by leveraging database access.
CVE-2015-7437
- EPSS 0.04%
- Veröffentlicht 02.01.2016 21:59:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
Queue Watcher in IBM Sterling B2B Integrator 5.2 allows local users to obtain sensitive information via unspecified vectors.
CVE-2015-7431
- EPSS 0.23%
- Veröffentlicht 02.01.2016 21:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Queue Watcher in IBM Sterling B2B Integrator 5.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVE-2015-7410
- EPSS 0.23%
- Veröffentlicht 01.01.2016 05:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Health Check tool in IBM Sterling B2B Integrator 5.2 does not properly use cookies in conjunction with HTTPS sessions, which allows man-in-the-middle attackers to obtain sensitive information or modify data via unspecified vectors.
CVE-2015-5019
- EPSS 0.13%
- Veröffentlicht 08.11.2015 22:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
IBM Sterling Integrator 5.1 before 5010004_8 and Sterling B2B Integrator 5.2 before 5020500_9 allow remote authenticated users to read or upload files by leveraging a password-change requirement.
CVE-2015-4992
- EPSS 0.13%
- Veröffentlicht 06.10.2015 01:59:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
IBM Sterling B2B Integrator 5.2 before 5020500_8 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.
- EPSS 1.88%
- Veröffentlicht 10.01.2015 02:59:27
- Zuletzt bearbeitet 12.04.2025 10:46:40
The HTTP Server Adapter in IBM Sterling B2B Integrator 5.1 and 5.2.x and Sterling File Gateway 2.1 and 2.2 allows remote attackers to cause a denial of service (connection-slot exhaustion) via a crafted HTTP request.
CVE-2014-6146
- EPSS 0.06%
- Veröffentlicht 08.11.2014 11:55:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
IBM Sterling B2B Integrator 5.2.x through 5.2.4, when the Connect:Direct Server Adapter is configured, does not properly process the logging configuration, which allows local users to obtain sensitive information by reading log files.
- EPSS 0.28%
- Veröffentlicht 26.10.2014 18:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Change Password feature in IBM Sterling B2B Integrator 5.2.x through 5.2.4 does not have a lockout protection mechanism for invalid login requests, which makes it easier for remote attackers to obtain admin access via a brute-force approach.