IBM Sterling Connect:Express Adapter
cpe:2.3:a:ibm:sterling_connect:express_for_unix:*:*:*:*:*:*:*
- >= 5.2.0.00, <= 5.2.0.12
A session fixation vulnerability has been identified in the IBM Sterling Connect:Express Adapter for Sterling B2B Integrator, specifically in versions 5.2.0.00 through 5.2.0.12. The vulnerability arises because the application does not invalidate session IDs after they have been used. This oversight could enable an authenticated user to impersonate another user within the system.
Exploitation of this vulnerability could allow an authenticated user to impersonate another user on the system.
Users can upgrade to version 5.2.0.13 to address this vulnerability. Instructions for downloading the update are available on the IBM Support Fix Central website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.