The Health Check tool in IBM Sterling B2B Integrator 5.2 does not properly use cookies in conjunction with HTTPS sessions, which allows man-in-the-middle attackers to obtain sensitive information or modify data via unspecified vectors.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/brianhigh/us-cert-bulletins