Vulnerability Description
IBM Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 and 1.0.0.3 before 1.0.0.3_2, when access by guests is enabled, place an internal hostname and a payload path in a response, which allows remote authenticated users to obtain sensitive information by leveraging a trading-partner relationship and reading response fields.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | B2B Advanced Communications | 1.0.0.1 |
Related Weaknesses (CWE)
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT10702
- http://www-01.ibm.com/support/docview.wss?uid=swg21967334PatchVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT10702
- http://www-01.ibm.com/support/docview.wss?uid=swg21967334PatchVendor Advisory
FAQ
What is CVE-2015-5022?
CVE-2015-5022 is a vulnerability with a CVSS score of 4.3 (MEDIUM). IBM Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 and 1.0.0.3 before 1.0.0.3_2, when access by guests is enabled, place an internal hostname and a pa...
How severe is CVE-2015-5022?
CVE-2015-5022 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-5022?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm B2B Advanced Communications.