CVE-2016-6020

Description

IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.

Risk Information

Base Score
6.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.267

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 5.2Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 5.2.4Windows
Vulnerabilities CVE-2014-6146,CVE-2014-6199,CVE-2016-6020,CVE-2017-1496 are affected in IBM Sterling B2B Integrator 5.2.1Windows
Vulnerabilities CVE-2014-6146,CVE-2014-6199,CVE-2016-6020,CVE-2017-1496 are affected in IBM Sterling B2B Integrator 5.2.2Windows
Vulnerabilities CVE-2014-6199,CVE-2016-6020 are affected in IBM Sterling B2B Integrator 5.2.4.1Windows
Vulnerabilities CVE-2014-6199,CVE-2016-6020 are affected in IBM Sterling B2B Integrator 5.2.4.2Windows
Vulnerabilities CVE-2016-6020,CVE-2017-1496 are affected in IBM Sterling B2B Integrator 5.2.5Windows
Vulnerabilities CVE-2016-6020,CVE-2017-1496,CVE-2018-1513 are affected in IBM Sterling B2B Integrator 5.2.6Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 5.2.6Windows
Vulnerabilities CVE-2016-6020,CVE-2017-1496,CVE-2017-6168 are affected in IBM Sterling B2B Integrator 5.2.5Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234