2025-01-28 03:03:52 +00:00
{
"id" : "CVE-2024-27263" ,
"sourceIdentifier" : "psirt@us.ibm.com" ,
"published" : "2025-01-28T01:15:08.950" ,
2025-03-16 03:03:50 +00:00
"lastModified" : "2025-03-05T15:41:10.337" ,
2025-03-09 03:03:50 +00:00
"vulnStatus" : "Analyzed" ,
2025-01-28 03:03:52 +00:00
"cveTags" : [ ] ,
"descriptions" : [
{
"lang" : "en" ,
"value" : "IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to obtain sensitive information from the dashboard UI using man in the middle techniques."
2025-02-02 03:03:49 +00:00
} ,
{
"lang" : "es" ,
"value" : "IBM Sterling B2B Integrator 6.0.0.0 a 6.1.2.5 y 6.2.0.0 a 6.2.0.1 podr\u00edan permitir que un usuario autenticado obtenga informaci\u00f3n confidencial de la interfaz de usuario del panel de control mediante t\u00e9cnicas de intermediario."
2025-01-28 03:03:52 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "psirt@us.ibm.com" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" ,
"baseScore" : 5.3 ,
"baseSeverity" : "MEDIUM" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "HIGH" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "NONE"
} ,
"exploitabilityScore" : 1.6 ,
"impactScore" : 3.6
}
]
} ,
"weaknesses" : [
{
"source" : "psirt@us.ibm.com" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-300"
}
]
2025-03-09 03:03:50 +00:00
} ,
{
"source" : "nvd@nist.gov" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-noinfo"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "6.0.0.0" ,
"versionEndIncluding" : "6.1.2.5" ,
"matchCriteriaId" : "E2DD03C2-67D3-4BA5-8109-10C84538AC3B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "6.2.0.0" ,
"versionEndIncluding" : "6.2.0.1" ,
"matchCriteriaId" : "ECA7E00E-2AD1-4AA7-BAA8-3E8A14F48D21"
}
]
}
]
2025-01-28 03:03:52 +00:00
}
] ,
"references" : [
{
"url" : "https://www.ibm.com/support/pages/node/7176072" ,
2025-03-09 03:03:50 +00:00
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Vendor Advisory"
]
2025-01-28 03:03:52 +00:00
}
]
}