{"id":2095,"date":"2025-04-28T22:33:37","date_gmt":"2025-04-28T22:33:37","guid":{"rendered":"http:\/\/localhost\/?p=2095"},"modified":"2025-04-28T22:33:37","modified_gmt":"2025-04-28T22:33:37","slug":"security-bulletin-apache-tomcat-vulnerabilities-affect-ibm-sterling-b2b-integrator","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=2095","title":{"rendered":"Security Bulletin: Apache Tomcat Vulnerabilities Affect IBM Sterling B2B Integrator"},"content":{"rendered":"<div class=\"vulnerability-details\">\n<h2>Vulnerability Details<\/h2>\n<div class=\"info-section\">\n<h3>Basic Information<\/h3>\n<table class=\"info-table\">\n<tr>\n<th>Title<\/th>\n<td>Security Bulletin: Apache Tomcat Vulnerabilities Affect IBM Sterling B2B Integrator<\/td>\n<\/tr>\n<tr>\n<th>Type<\/th>\n<td>ibm<\/td>\n<\/tr>\n<tr>\n<th>Published<\/th>\n<td>2025-04-28T20:41:23<\/td>\n<\/tr>\n<tr>\n<th>Last Seen<\/th>\n<td>2025-04-29T02:56:42<\/td>\n<\/tr>\n<tr>\n<th>CVSS Score<\/th>\n<td style=\"color: #cc0000; font-weight: bold;\">9.8 (CRITICAL)<\/td>\n<\/tr>\n<\/table><\/div>\n<div class=\"cvss-section\">\n<h3>CVSS v3 Details<\/h3>\n<table class=\"cvss-table\">\n<tr>\n<th>Attack Vector<\/th>\n<td>NETWORK<\/td>\n<\/tr>\n<tr>\n<th>Attack Complexity<\/th>\n<td>LOW<\/td>\n<\/tr>\n<tr>\n<th>Privileges Required<\/th>\n<td>NONE<\/td>\n<\/tr>\n<tr>\n<th>User Interaction<\/th>\n<td>NONE<\/td>\n<\/tr>\n<tr>\n<th>Scope<\/th>\n<td>UNCHANGED<\/td>\n<\/tr>\n<tr>\n<th>Confidentiality Impact<\/th>\n<td>HIGH<\/td>\n<\/tr>\n<tr>\n<th>Integrity Impact<\/th>\n<td>HIGH<\/td>\n<\/tr>\n<tr>\n<th>Availability Impact<\/th>\n<td>HIGH<\/td>\n<\/tr>\n<\/table><\/div>\n<div class=\"cve-section\">\n<h3>CVE Information<\/h3>\n<table class=\"cve-table\">\n<tr>\n<th>CVE IDs<\/th>\n<td>CVE-2006-7197, CVE-2011-3190, CVE-2013-2185, CVE-2014-0230, CVE-2016-0714, CVE-2016-5018, CVE-2016-5388, CVE-2016-6796, CVE-2016-6797, CVE-2016-6816, CVE-2016-8735, CVE-2017-5647, CVE-2020-8022<\/td>\n<\/tr>\n<tr>\n<th>CWE<\/th>\n<td><\/td>\n<\/tr>\n<tr>\n<th>Bulletin Family<\/th>\n<td>software<\/td>\n<\/tr>\n<\/table><\/div>\n<div class=\"description-section\">\n<h3>Description<\/h3>\n<div class=\"description-content\">\n            ## Summary<\/p>\n<p>IBM Sterling B2B Integrator has addressed the security vulnerabilities.<\/p>\n<p>## Vulnerability Details<\/p>\n<p>**CVEID:**CVE-2016-8735<br \/>\n**DESCRIPTION:** Apache Tomcat could allow a remote attacker to execute arbitrary code on the system, caused by an error in the JmxRemoteLifecycleListener. By sending specially crafted data to a JMX port, an attacker could exploit this vulnerability to execute arbitrary code on the system with elevated privileges.<br \/>\nCVSS Base score: 7.3<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/119157 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:L)  <\/p>\n<p>**CVEID:**CVE-2016-0714<br \/>\n**DESCRIPTION:** Apache Tomcat could allow a remote attacker to bypass security restrictions, caused by an error in multiple session persistence mechanisms. By placing a malicious object into a session, an attacker could exploit this vulnerability to bypass a security manager and possibly execute arbitrary code on the system.<br \/>\nCVSS Base score: 7.3<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/110856 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:L)  <\/p>\n<p>**CVEID:**CVE-2016-5388<br \/>\n**DESCRIPTION:** Apache Tomcat could allow a remote attacker to redirect HTTP traffic of CGI application, caused by the failure to protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable. By using a specially-crafted Proxy header in a HTTP request, an attacker could exploit this vulnerability to redirect outbound HTTP traffic to arbitrary proxy server. This is also known as the &#8220;HTTPOXY&#8221; vulnerability.<br \/>\nCVSS Base score: 8.1<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/115091 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H)  <\/p>\n<p>**CVEID:**CVE-2020-8022<br \/>\n**DESCRIPTION:** tomcat package for openSUSE could allow a local authenticated attacker to gain elevated privileges on the system, caused by an incorrect default permission flaw. By sending a specially-crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges as root.<br \/>\nCVSS Base score: 7.8<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/184110 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:L\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H)  <\/p>\n<p>**CVEID:**CVE-2014-0230<br \/>\n**DESCRIPTION:** Apache Tomcat is vulnerable to a denial of service, caused by an error when an HTTP response is returned before the entire request body is fully read. An attacker could exploit this vulnerability using a series of aborted upload attempts to cause a denial of service.<br \/>\nCVSS Base score: 5<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/102131 for the current score.<br \/>\nCVSS Vector: (AV:N\/AC:L\/Au:N\/C:N\/I:N\/A:P)  <\/p>\n<p>**CVEID:**CVE-2016-5018<br \/>\n**DESCRIPTION:** Apache Tomcat could allow a local attacker to bypass security restrictions. An attacker could exploit this vulnerability using a Tomcat utility method to bypass a configured SecurityManager.<br \/>\nCVSS Base score: 4<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/118406 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:L\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N)  <\/p>\n<p>**CVEID:**CVE-2017-5647<br \/>\n**DESCRIPTION:** Apache Tomcat could allow a remote attacker to obtain sensitive information, caused by an error in the processing of pipelined requests in send file. An attacker could exploit this vulnerability to obtain sensitive information from the wrong response.<br \/>\nCVSS Base score: 5.3<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/124400 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N)  <\/p>\n<p>**CVEID:**CVE-2016-6797<br \/>\n**DESCRIPTION:** Apache Tomcat could allow a local attacker to gain unauthorized access to the system, caused by an error in the ResourceLinkFactory. An attacker could exploit this vulnerability to gain access to arbitrary global JNDI resources.<br \/>\nCVSS Base score: 4<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/118403 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:L\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N)  <\/p>\n<p>**CVEID:**CVE-2016-6796<br \/>\n**DESCRIPTION:** Apache Tomcat could allow a local attacker to bypass security restrictions. By modifying configuration parameters for the JSP Servlet, an attacker could exploit this vulnerability to bypass a configured SecurityManager.<br \/>\nCVSS Base score: 4<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/118404 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:L\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N)  <\/p>\n<p>**CVEID:**CVE-2013-2185<br \/>\n**DESCRIPTION:** Red Hat JBoss Enterprise Application Platform could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions by the implementation of the DiskFileItem class. By sending a specially-crafted HTTP request, a remote attacker could exploit this vulnerability using serialized instance of the DiskFileItem class to upload a file containing a NULL byte, which could allow the attacker to execute arbitrary PHP code on the vulnerable system.<br \/>\nCVSS Base score: 6<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/87273 for the current score.<br \/>\nCVSS Vector: (AV:N\/AC:M\/Au:S\/C:P\/I:P\/A:P)  <\/p>\n<p>**CVEID:**CVE-2011-3190<br \/>\n**DESCRIPTION:** Apache Tomcat could allow a remote attacker to bypass security restrictions, caused by the improper handling of messages by the AJP protocol. A remote attacker could exploit this vulnerability to inject arbitrary AJP messages to bypass the authentication process and possibly obtain sensitive information.<br \/>\nCVSS Base score: 7.5<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/69472 for the current score.<br \/>\nCVSS Vector: (AV:N\/AC:L\/Au:N\/C:P\/I:P\/A:P)  <\/p>\n<p>**CVEID:**CVE-2016-6816<br \/>\n**DESCRIPTION:** Apache Tomcat is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject arbitrary HTTP headers and cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning or cross-site scripting, and possibly obtain sensitive information.<br \/>\nCVSS Base score: 6.1<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/119158 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N)  <\/p>\n<p>**CVEID:**CVE-2006-7197<br \/>\n**DESCRIPTION:** Apache Tomcat could allow a remote attacker to obtain sensitive information, caused by a buffer over-read error in the AJP connector&#8217;s ajp_process_callback function in the mod_jk module. A remote attacker could exploit this vulnerability to view portions of system memory.<br \/>\nCVSS Base score: 3.5<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/34068 for the current score.<br \/>\nCVSS Vector:<\/p>\n<p>## Affected Products and Versions<\/p>\n<p>Affected Product(s) | APAR(s) | Version(s)<br \/>\n&#8212;|&#8212;|&#8212;<br \/>\nIBM Sterling B2B Integrator | IT37682 | 5.2.0.0 &#8211; 5.2.6.5_4<br \/>\nIBM Sterling B2B Integrator | IT37682 | 6.0.0.0 &#8211; 6.0.0.6, 6.0.1.0 &#8211; 6.0.3.4<br \/>\nIBM Sterling B2B Integrator | IT37682 | 6.1.0.0 &#8211; 6.1.0.2  <\/p>\n<p>## Remediation\/Fixes<\/p>\n<p>Product &#038; Version | Remediation &#038; Fix<br \/>\n&#8212;|&#8212;<br \/>\n5.2.0.0 &#8211; 5.2.6.5_4 | Apply IBM Sterling B2B Integrator version 6.0.0.7, 6.0.3.5, 6.1.0.3, or 6.1.1.0 on Fix Central<br \/>\n6.0.0.0 &#8211; 6.0.0.6, 6.0.1.0 &#8211; 6.0.3.4 | Apply IBM Sterling B2B Integrator version 6.0.0.7, 6.0.3.5, 6.1.0.3 or 6.1.1.0 on Fix Central<br \/>\n6.1.0.0 &#8211; 6.1.0.2 | Apply IBM Sterling B2B Integrator version 6.1.0.3 or 6.1.1.0 on Fix Central  <\/p>\n<p>## Workarounds and Mitigations<\/p>\n<p>None<\/p>\n<p>##\n        <\/p><\/div>\n<\/p><\/div>\n<div class=\"impact-section\">\n<h3>Impact Assessment<\/h3>\n<table class=\"impact-table\">\n<tr>\n<th>Base Score<\/th>\n<td>9.8<\/td>\n<\/tr>\n<tr>\n<th>Severity<\/th>\n<td style=\"color: #cc0000;\">CRITICAL<\/td>\n<\/tr>\n<\/table><\/div>\n<div class=\"source-link\">\n<p><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6495961\" target=\"_blank\">View full CVE details<\/a><\/p>\n<\/p><\/div>\n<\/div>\n<style>\n.vulnerability-details {\n    font-family: Arial, sans-serif;\n    max-width: 1200px;\n    margin: 0 auto;\n    padding: 20px;\n}<\/p>\n<p>.info-section, .cvss-section, .cve-section, .description-section, .impact-section {\n    margin-bottom: 30px;\n    background: #f8f9fa;\n    padding: 20px;\n    border-radius: 8px;\n    box-shadow: 0 2px 4px rgba(0,0,0,0.1);\n}<\/p>\n<p>h2 {\n    color: #2c3e50;\n    border-bottom: 2px solid #3498db;\n    padding-bottom: 10px;\n    margin-bottom: 20px;\n}<\/p>\n<p>h3 {\n    color: #34495e;\n    margin-bottom: 15px;\n}<\/p>\n<p>.info-table, .cvss-table, .cve-table, .impact-table {\n    width: 100%;\n    border-collapse: collapse;\n    margin-bottom: 20px;\n}<\/p>\n<p>.info-table th, .cvss-table th, .cve-table th, .impact-table th {\n    background: #e9ecef;\n    padding: 12px;\n    text-align: left;\n    width: 200px;\n}<\/p>\n<p>.info-table td, .cvss-table td, .cve-table td, .impact-table td {\n    padding: 12px;\n    border-bottom: 1px solid #dee2e6;\n}<\/p>\n<p>.description-content {\n    line-height: 1.6;\n    color: #2c3e50;\n}<\/p>\n<p>.source-link {\n    text-align: center;\n    margin-top: 30px;\n}<\/p>\n<p>.source-link a {\n    display: inline-block;\n    padding: 10px 20px;\n    background: #3498db;\n    color: white;\n    text-decoration: none;\n    border-radius: 5px;\n    transition: background 0.3s;\n}<\/p>\n<p>.source-link a:hover {\n    background: #2980b9;\n}\n<\/style>\n","protected":false},"excerpt":{"rendered":"<p>Vulnerability Details Basic Information Title Security Bulletin: Apache Tomcat Vulnerabilities Affect IBM Sterling B2B Integrator Type ibm Published 2025-04-28T20:41:23 Last Seen 2025-04-29T02:56:42 CVSS Score 9.8&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[9,6,8,35,12,76,13,7,11,5],"class_list":["post-2095","post","type-post","status-publish","format-standard","hentry","category-category_cve","tag-critical","tag-cve","tag-cvss","tag-cvss-98","tag-exploit","tag-ibm","tag-news","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Security Bulletin: Apache Tomcat Vulnerabilities Affect IBM Sterling B2B Integrator - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=2095\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Security Bulletin: Apache Tomcat Vulnerabilities Affect IBM Sterling B2B Integrator - zero redgem\" \/>\n<meta property=\"og:description\" content=\"Vulnerability Details Basic Information Title Security Bulletin: Apache Tomcat Vulnerabilities Affect IBM Sterling B2B Integrator Type ibm Published 2025-04-28T20:41:23 Last Seen 2025-04-29T02:56:42 CVSS Score 9.8...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=2095\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-04-28T22:33:37+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=2095#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=2095\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Security Bulletin: Apache Tomcat Vulnerabilities Affect IBM Sterling B2B Integrator\",\"datePublished\":\"2025-04-28T22:33:37+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=2095\"},\"wordCount\":1300,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CRITICAL\",\"CVE\",\"CVSS\",\"CVSS-9.8\",\"exploit\",\"ibm\",\"news\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_cve\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=2095#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=2095\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=2095\",\"name\":\"Security Bulletin: Apache Tomcat Vulnerabilities Affect IBM Sterling B2B Integrator - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-04-28T22:33:37+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=2095#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=2095\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=2095#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security Bulletin: Apache Tomcat Vulnerabilities Affect IBM Sterling B2B Integrator\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Security Bulletin: Apache Tomcat Vulnerabilities Affect IBM Sterling B2B Integrator - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=2095","og_locale":"en_US","og_type":"article","og_title":"Security Bulletin: Apache Tomcat Vulnerabilities Affect IBM Sterling B2B Integrator - zero redgem","og_description":"Vulnerability Details Basic Information Title Security Bulletin: Apache Tomcat Vulnerabilities Affect IBM Sterling B2B Integrator Type ibm Published 2025-04-28T20:41:23 Last Seen 2025-04-29T02:56:42 CVSS Score 9.8...","og_url":"https:\/\/zero.redgem.net\/?p=2095","og_site_name":"zero redgem","article_published_time":"2025-04-28T22:33:37+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=2095#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=2095"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Security Bulletin: Apache Tomcat Vulnerabilities Affect IBM Sterling B2B Integrator","datePublished":"2025-04-28T22:33:37+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=2095"},"wordCount":1300,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CRITICAL","CVE","CVSS","CVSS-9.8","exploit","ibm","news","Security","tapic","Vulnerability"],"articleSection":["category_cve"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=2095#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=2095","url":"https:\/\/zero.redgem.net\/?p=2095","name":"Security Bulletin: Apache Tomcat Vulnerabilities Affect IBM Sterling B2B Integrator - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-04-28T22:33:37+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=2095#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=2095"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=2095#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Security Bulletin: Apache Tomcat Vulnerabilities Affect IBM Sterling B2B Integrator"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/2095","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2095"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/2095\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2095"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2095"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2095"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}