IBM Security Bulletin: User permission vulnerability affects IBM Sterling B2B Integrator (CVE-2017-1326)

IBM Sterling File Gateway does not properly restrict user requests based on permission level. This allows for users to update data related to other users, by manipulating the parameters passed in the POST request.

CVE(s): CVE-2017-1326

Affected product(s) and affected version(s):

IBM Sterling B2B Integrator 5.2

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2sVxDte
X-Force Database: http://ift.tt/2rCTS3x

The post IBM Security Bulletin: User permission vulnerability affects IBM Sterling B2B Integrator (CVE-2017-1326) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2sVBZ3G