Ibm Sterling B2B Integrator vulnerabilities

195 known vulnerabilities affecting ibm/sterling_b2b_integrator.

Total CVEs
195
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH28MEDIUM152LOW8

Vulnerabilities

Page 2 of 10
CVE-2025-1349MEDIUMCVSS 4.8≥ 6.0.0.0, < 6.1.2.7≥ 6.2, < 6.2.0.5+2 more2025-06-18
CVE-2025-1349 [MEDIUM] CWE-79 CVE-2025-1349: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 throug IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted
cvelistv5nvd
CVE-2024-54172MEDIUMCVSS 4.3≥ 6.0.0.0, < 6.1.2.7≥ 6.2, < 6.2.0.5+2 more2025-06-18
CVE-2024-54172 [MEDIUM] CWE-352 CVE-2024-54172: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 throug IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
cvelistv5nvd
CVE-2025-1348MEDIUMCVSS 4.0≥ 6.0.0.0, < 6.1.2.7≥ 6.2, < 6.2.0.5+2 more2025-06-18
CVE-2025-1348 [MEDIUM] CWE-525 CVE-2025-1348: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 throug IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 could allow a local user to obtain sensitive information from a user’s web browser cache due to not using a suitable caching policy.
cvelistv5nvd
CVE-2024-56338MEDIUMCVSS 4.8≥ 6.0.0.0, ≤ 6.1.2.6 ≥ 6.2, ≤ 6.2.0.3 2025-03-11
CVE-2024-56338 [MEDIUM] CWE-79 CVE-2024-56338: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 is IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2024-52905LOWCVSS 2.7≥ 6.0.0.0, < 6.1.2.7≥ 6.2, < 6.2.0.42025-03-10
CVE-2024-52905 [LOW] CWE-497 CVE-2024-52905: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 cou IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 could disclose sensitive database information to a privileged user.
nvd
CVE-2023-38739HIGHCVSS 8.8≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2.0.0, ≤ 6.2.0.32025-01-31
CVE-2023-38739 [MEDIUM] CWE-352 CVE-2023-38739: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to cro IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
cvelistv5nvd
CVE-2024-47103MEDIUMCVSS 5.4≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2.0.0, ≤ 6.2.0.32025-01-31
CVE-2024-47103 [MEDIUM] CWE-79 CVE-2024-47103: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
cvelistv5nvd
CVE-2024-47116MEDIUMCVSS 5.4≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2.0.0, ≤ 6.2.0.32025-01-31
CVE-2024-47116 [MEDIUM] CWE-79 CVE-2024-47116: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
cvelistv5nvd
CVE-2024-40696MEDIUMCVSS 5.4≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2.0.0, ≤ 6.2.0.32025-01-31
CVE-2024-40696 [MEDIUM] CWE-79 CVE-2024-40696: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
cvelistv5nvd
CVE-2024-49807MEDIUMCVSS 5.4≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2.0.0, ≤ 6.2.0.32025-01-31
CVE-2024-49807 [MEDIUM] CWE-79 CVE-2024-49807: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
cvelistv5nvd
CVE-2024-45089MEDIUMCVSS 4.3≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2.0.0, ≤ 6.2.0.32025-01-31
CVE-2024-45089 [MEDIUM] CWE-203 CVE-2024-45089: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition EBI IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition EBICS server could allow an authenticated user to obtain sensitive filename information due to an observable discrepancy.
cvelistv5nvd
CVE-2023-50316CRITICALCVSS 9.8≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2.0.0, ≤ 6.2.0.12025-01-28
CVE-2023-50316 [MEDIUM] CWE-89 CVE-2023-50316: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 is vulnerable to SQL IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
cvelistv5nvd
CVE-2024-27263MEDIUMCVSS 5.3≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2.0.0, ≤ 6.2.0.12025-01-28
CVE-2024-27263 [MEDIUM] CWE-300 CVE-2024-27263: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authe IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to obtain sensitive information from the dashboard UI using man in the middle techniques.
cvelistv5nvd
CVE-2023-50309MEDIUMCVSS 5.4≥ 6.0.0.0, ≤ 6.1.2.5v6.2.0.02025-01-23
CVE-2023-50309 [MEDIUM] CWE-79 CVE-2023-50309: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to stored cross-site s IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2023-32340MEDIUMCVSS 5.4≥ 6.0.0.0, ≤ 6.1.2.5v6.2.0.02025-01-23
CVE-2023-32340 [MEDIUM] CWE-79 CVE-2023-32340: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to cross-site scriptin IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2024-31903HIGHCVSS 8.8≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2.0.0, ≤ 6.2.0.22025-01-22
CVE-2024-31903 [HIGH] CWE-502 CVE-2024-31903: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 all IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 allow an attacker on the local network to execute arbitrary code on the system, caused by the deserialization of untrusted data.
nvd
CVE-2024-31913MEDIUMCVSS 5.4≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2.0.0, ≤ 6.2.0.22025-01-06
CVE-2024-31913 [MEDIUM] CWE-79 CVE-2024-31913: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2024-31914MEDIUMCVSS 6.4≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2, ≤ 6.2.0.22025-01-06
CVE-2024-31914 [MEDIUM] CWE-79 CVE-2024-31914: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2021-20553MEDIUMCVSS 5.4≥ 5.2.0.0, ≤ 6.1.1.0≥ 6.0.0.0, ≤ 6.0.0.6+2 more2024-12-19
CVE-2021-20553 [MEDIUM] CWE-79 CVE-2021-20553: IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site scr IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
cvelistv5nvd
CVE-2023-42010LOWCVSS 3.7≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2.0.0, ≤ 6.2.0.22024-07-17
CVE-2023-42010 [LOW] CWE-497 CVE-2023-42010: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 cou IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 could disclose sensitive information in the HTTP response using man in the middle techniques. IBM X-Force ID: 265507.
nvd