IBM Sterling File Gateway does not properly restrict user requests based on permission level. This allows for users to update data related to other users, by manipulating the parameters passed in the POST request. IBM X-Force ID: 126060.
References
Link | Resource |
---|---|
http://www.ibm.com/support/docview.wss?uid=swg22004274 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/99183 | Third Party Advisory VDB Entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/126060 | VDB Entry Vendor Advisory |
http://www.ibm.com/support/docview.wss?uid=swg22004274 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/99183 | Third Party Advisory VDB Entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/126060 | VDB Entry Vendor Advisory |
Configurations
History
21 Nov 2024, 03:21
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.ibm.com/support/docview.wss?uid=swg22004274 - Patch, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/99183 - Third Party Advisory, VDB Entry | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/126060 - VDB Entry, Vendor Advisory |
Information
Published : 2017-06-22 18:29
Updated : 2024-11-21 03:21
NVD link : CVE-2017-1326
Mitre link : CVE-2017-1326
CVE.ORG link : CVE-2017-1326
JSON object : View
Products Affected
ibm
- sterling_b2b_integrator
CWE
CWE-269
Improper Privilege Management