CVE-2013-0539
 
Severity Score
5.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
An unspecified third-party component in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 uses short session ID values, which makes it easier for remote attackers to hijack sessions, and consequently obtain sensitive information, via a brute-force attack.
Un componente de terceros no especificado en BM Sterling B2B Integrator v5.1 y v5.2 y Sterling File Gateway v2.1 y v2.2 utiliza los valores de ID de sesión corta, lo que hace que sea más fácil para los atacantes remotos secuestrar sesiones, y por lo tanto obtener información sensible, a través de ataques de fuerza bruta.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2012-12-16 CVE Reserved
- 2013-07-03 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-255: Credentials Management Errors
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/82916 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg1IC92007 | 2017-08-29 | |
http://www-01.ibm.com/support/docview.wss?uid=swg21640830 | 2017-08-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Sterling B2b Integrator Search vendor "Ibm" for product "Sterling B2b Integrator" | 5.1 Search vendor "Ibm" for product "Sterling B2b Integrator" and version "5.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Sterling B2b Integrator Search vendor "Ibm" for product "Sterling B2b Integrator" | 5.2 Search vendor "Ibm" for product "Sterling B2b Integrator" and version "5.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Sterling File Gateway Search vendor "Ibm" for product "Sterling File Gateway" | 2.1 Search vendor "Ibm" for product "Sterling File Gateway" and version "2.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Sterling File Gateway Search vendor "Ibm" for product "Sterling File Gateway" | 2.2 Search vendor "Ibm" for product "Sterling File Gateway" and version "2.2" | - |
Affected
|