Ibm Sterling B2B Integrator vulnerabilities
197 known vulnerabilities affecting ibm/sterling_b2b_integrator.
Total CVEs
197
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH29MEDIUM153LOW8
Vulnerabilities
Page 2 of 10
CVE-2020-4700P3HIGHCVSS 8.8≥ 5.2.0.0, ≤ 5.2.6.5≥ 6.0.0.0, ≤ 6.0.3.2+4 more2020-11-16
CVE-2020-4700 [HIGH] CVE-2020-4700: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 cou
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 could allow an authenticated user belonging to a specific user group to create a user or group with administrative privileges. IBM X-Force ID: 187077.
nvd
CVE-2017-1192P3HIGHCVSS 8.2v5.2v5.2.4+5 more2017-08-10
CVE-2017-1192 [HIGH] CWE-611 CVE-2017-1192: IBM Sterling B2B Integrator 5.2 is vulnerable to an XML External Entity Injection (XXE) attack when
IBM Sterling B2B Integrator 5.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 123663.
nvd
CVE-2025-36368P3HIGHCVSS 7.2≥ 6.1.0.0, < 6.1.2.8≥ 6.2.0.0, < 6.2.0.5_2+4 more2026-03-13
CVE-2025-36368 [HIGH] CWE-89 CVE-2025-36368: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, and 6.2.1.0 through 6.2.1.1_1 are vulnerable to SQL injection. An administrative user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
nvd
CVE-2014-0927P3HIGHCVSS 8.1v5.1v5.22018-04-20
CVE-2014-0927 [HIGH] CWE-287 CVE-2014-0927: The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gatew
The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to bypass authentication by leveraging knowledge of the port number and webapp path. IBM X-Force ID: 92259.
nvd
CVE-2022-40231P3HIGHCVSS 8.8≥ 6.0.0.0, ≤ 6.0.3.7≥ 6.1.0.0, ≤ 6.1.2.02023-02-17
CVE-2022-40231 [HIGH] CVE-2022-40231: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 cou
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 could allow an authenticated user to perform unauthorized actions due to improper access controls. IBM X-Force ID: 235533.
nvd
CVE-2025-14031P3HIGHCVSS 7.5≥ 6.1.0.0, < 6.1.2.8≥ 6.2.0.0, < 6.2.0.5_2+5 more2026-03-17
CVE-2025-14031 [HIGH] CWE-77 CVE-2025-14031: IBM Sterling B2B Integrator and and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 thr
IBM Sterling B2B Integrator and and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 could allow an unauthenticated attacker to send a specially crafted request that causes the application to crash.
nvd
CVE-2021-20584P3HIGHCVSS 7.5≥ 2.2.0.0, ≤ 5.2.6.5_4≥ 6.0.0.0, ≤ 6.0.0.6+2 more2021-10-07
CVE-2021-20584 [HIGH] CVE-2021-20584: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote attacker to upload arbitrary
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote attacker to upload arbitrary files, caused by improper access controls. IBM X-Force ID: 199397.
nvd
CVE-2022-40232P3HIGHCVSS 8.8≥ 6.1.0.0, ≤ 6.1.1.1v6.1.2.02023-02-17
CVE-2022-40232 [HIGH] CWE-276 CVE-2022-40232: IBM Sterling B2B Integrator Standard Edition 6.1.0.0 through 6.1.1.1, and 6.1.2.0 could allow an au
IBM Sterling B2B Integrator Standard Edition 6.1.0.0 through 6.1.1.1, and 6.1.2.0 could allow an authenticated user to perform actions they should not have access to due to improper permission controls. IBM X-Force ID: 235597.
nvd
CVE-2019-4043P3HIGHCVSS 7.1≥ 5.2, ≤ 5.2.6.4v6.0.0.0+1 more2019-04-02
CVE-2019-4043 [HIGH] CWE-611 CVE-2019-4043: IBM Sterling B2B Integrator Standard Edition 5.2.0 snf 6.0.0.0 is vulnerable to an XML External Enti
IBM Sterling B2B Integrator Standard Edition 5.2.0 snf 6.0.0.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 156239.
nvd
CVE-2025-36134P3HIGHCVSS 7.5≥ 6.0.0.0, < 6.1.2.7_2≥ 6.2.0.0, < 6.2.0.5_1+3 more2025-11-25
CVE-2025-36134 [HIGH] CWE-1275 CVE-2025-36134: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 throug
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie.
nvd
CVE-2019-4598P3MEDIUMCVSS 6.3≥ 5.2.0.0, ≤ 5.2.6.5v5.2.0.0+1 more2020-02-26
CVE-2019-4598 [MEDIUM] CWE-89 CVE-2019-4598: IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection.
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 167881.
nvd
CVE-2019-4597P3MEDIUMCVSS 6.3≥ 5.2.0.0, ≤ 5.2.6.5v5.2.0.0+1 more2020-02-26
CVE-2019-4597 [MEDIUM] CWE-89 CVE-2019-4597: IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection.
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 167880.
nvd
CVE-2026-1264P3MEDIUMCVSS 6.5≥ 6.1.0.0, < 6.1.2.8≥ 6.2.0.0, < 6.2.0.5_2+5 more2026-03-17
CVE-2026-1264 [MEDIUM] CWE-306 CVE-2026-1264: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 allows a remote unauthenticated attacker to view and delete the partners of a community and to delete the communities.
nvd
CVE-2015-0194P3MEDIUMCVSS 6.5v5.1v5.22017-08-02
CVE-2015-0194 [MEDIUM] CWE-611 CVE-2015-0194: XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling
XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling File Gateway 2.1 and 2.2 allows remote attackers to read arbitrary files via a crafted XML data.
nvd
CVE-2022-35638P3HIGHCVSS 8.8≥ 6.0.0.0, < 6.0.3.9≥ 6.1.0.0, < 6.1.2.3+2 more2023-11-22
CVE-2022-35638 [HIGH] CWE-352 CVE-2022-35638: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 is
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230824.
nvd
CVE-2023-38739P3HIGHCVSS 8.8≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2.0.0, ≤ 6.2.0.32025-01-31
CVE-2023-38739 [HIGH] CWE-352 CVE-2023-38739: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to cro
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
nvd
CVE-2020-4668P3HIGHCVSS 8.8≥ 6.0.0.0, ≤ 6.0.3.5≥ 6.1.0.0, ≤ 6.1.0.3+5 more2022-04-08
CVE-2020-4668 [HIGH] CWE-352 CVE-2020-4668: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 186283.
nvd
CVE-2020-4937P3HIGHCVSS 7.5≥ 5.2.0.0, ≤ 6.0.3.2v5.2.0.0+1 more2020-11-20
CVE-2020-4937 [HIGH] CWE-327 CVE-2020-4937: IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.2 uses weaker than expected crypt
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 191814.
nvd
CVE-2021-38925P3HIGHCVSS 7.5≥ 5.2.0.0, ≤ 6.0.3.4≥ 6.1.0.0, ≤ 6.1.0.3+4 more2021-10-06
CVE-2021-38925 [HIGH] CWE-326 CVE-2021-38925: IBM Sterling B2B Integrator Standard Edition 5.2.0. 0 through 6.1.1.0 uses weaker than expected cryp
IBM Sterling B2B Integrator Standard Edition 5.2.0. 0 through 6.1.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210171.
nvd
CVE-2021-29837P3HIGHCVSS 8.8≥ 5.2.0.0, ≤ 6.0.3.4≥ 6.1.0.0, ≤ 6.1.0.3+4 more2021-10-06
CVE-2021-29837 [HIGH] CWE-352 CVE-2021-29837: IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site req
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 204913.
nvd