IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not invalidate a session upon a logout action, which allows remote attackers to bypass authentication by leveraging an unattended workstation.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sterling_b2b_integrator | Ibm | 5.2 (including) | 5.2 (including) |
Sterling_file_gateway | Ibm | 2.2 (including) | 2.2 (including) |