IBM Sterling File Gateway does not properly restrict user requests based on permission level. This allows for users to update data related to other users, by manipulating the parameters passed in the POST request. IBM X-Force ID: 126060.
References
Link | Resource |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/126060 | VDB Entry Vendor Advisory |
http://www.ibm.com/support/docview.wss?uid=swg22004274 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/99183 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2017-06-22 11:29
Updated : 2019-10-02 17:03
NVD link : CVE-2017-1326
Mitre link : CVE-2017-1326
JSON object : View
CWE
CWE-269
Improper Privilege Management
Products Affected
ibm
- sterling_b2b_integrator