Vulnerability Description
The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to bypass authentication by leveraging knowledge of the port number and webapp path. IBM X-Force ID: 92259.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Sterling B2B Integrator | 5.1 |
| Ibm | Sterling File Gateway | 2.1 |
Related Weaknesses (CWE)
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21674739PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/92259VDB EntryVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21674739PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/92259VDB EntryVendor Advisory
FAQ
What is CVE-2014-0927?
CVE-2014-0927 is a vulnerability with a CVSS score of 8.1 (HIGH). The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to bypass authentication by leveraging knowledge of the port ...
How severe is CVE-2014-0927?
CVE-2014-0927 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-0927?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Sterling B2B Integrator, Ibm Sterling File Gateway.