CVE-2016-6020
Description
IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
Risk Information
Base Score
6.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.267
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 5.2 | Windows |
| Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 5.2.4 | Windows |
| Vulnerabilities CVE-2014-6146,CVE-2014-6199,CVE-2016-6020,CVE-2017-1496 are affected in IBM Sterling B2B Integrator 5.2.1 | Windows |
| Vulnerabilities CVE-2014-6146,CVE-2014-6199,CVE-2016-6020,CVE-2017-1496 are affected in IBM Sterling B2B Integrator 5.2.2 | Windows |
| Vulnerabilities CVE-2014-6199,CVE-2016-6020 are affected in IBM Sterling B2B Integrator 5.2.4.1 | Windows |
| Vulnerabilities CVE-2014-6199,CVE-2016-6020 are affected in IBM Sterling B2B Integrator 5.2.4.2 | Windows |
| Vulnerabilities CVE-2016-6020,CVE-2017-1496 are affected in IBM Sterling B2B Integrator 5.2.5 | Windows |
| Vulnerabilities CVE-2016-6020,CVE-2017-1496,CVE-2018-1513 are affected in IBM Sterling B2B Integrator 5.2.6 | Windows |
| Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 5.2.6 | Windows |
| Vulnerabilities CVE-2016-6020,CVE-2017-1496,CVE-2017-6168 are affected in IBM Sterling B2B Integrator 5.2.5 | Windows |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234