Security Bulletin
Summary
IBM Sterling B2B Integrator uses ActiveMQ. ActiveMQ uses Axis and is vulnerable.
Vulnerability Details
CVEID: CVE-2012-5784
DESCRIPTION: Apache Axis 1.4, as used in multiple products, could allow a remote attacker to conduct spoofing attacks, caused by the failure to verify that the server hostname matches a domain name in the subject''s Common Name (CN) field of the X.509 certificate. An attacker could exploit this vulnerability using man-in-the-middle techniques to spoof an SSL server and launch further attacks against a vulnerable target.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/79829 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVEID: CVE-2014-3596
DESCRIPTION: Apache Axis and Axis2 could allow a remote attacker to conduct spoofing attacks, caused by and incomplete fix related to the failure to verify that the server hostname matches a domain name in the subject''s Common Name (CN) field of the X.509 certificate. By persuading a victim to visit a Web site containing a specially-crafted certificate, an attacker could exploit this vulnerability using man-in-the-middle techniques to spoof an SSL server.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/95377 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Affected Products and Versions
IBM Sterling B2B Integrator 5.2.0.1 - 5.2.6.3
Remediation/Fixes
PRODUCT & Version |
Remediation/Fix |
IBM Sterling B2B Integrator 5.2.0.1 - 5.2.6.3 |
Apply IBM Sterling B2B Integrator version 6.0.0.0 or 5.2.6.4 available on Fix Central |
Workarounds and Mitigations
None
Get Notified about Future Security Bulletins
References
Change History
24 August 2018: Original version published
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Internal Use Only
For PSIRT product record 110113
Was this topic helpful?
Document Information
Modified date:
04 February 2020
UID
ibm10728839