Ibm Sterling B2B Integrator vulnerabilities
197 known vulnerabilities affecting ibm/sterling_b2b_integrator.
Total CVEs
197
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH29MEDIUM153LOW8
Vulnerabilities
Page 3 of 10
CVE-2018-1720P3HIGHCVSS 7.5v5.2.0.1v5.2.6.3_6+2 more2019-04-25
CVE-2018-1720 [HIGH] CWE-327 CVE-2018-1720: IBM Sterling B2B Integrator Standard Edition 5.2.0.1, 5.2.6.3_6, 6.0.0.0, and 6.0.0.1 uses weaker th
IBM Sterling B2B Integrator Standard Edition 5.2.0.1, 5.2.6.3_6, 6.0.0.0, and 6.0.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 147294.
nvd
CVE-2025-14483P3MEDIUMCVSS 6.5≥ 6.1.0.0, < 6.1.2.8≥ 6.2.0.0, < 6.2.0.5_2+5 more2026-03-13
CVE-2025-14483 [MEDIUM] CWE-201 CVE-2025-14483: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 could disclose sensitive host information to authenticated users in responses that could be used in further attacks against the system.
nvd
CVE-2025-2988P3MEDIUMCVSS 6.5≥ 6.0.0.0, < 6.1.2.7_1≥ 6.2.0.0, < 6.2.0.5+3 more2025-08-19
CVE-2025-2988 [MEDIUM] CWE-497 CVE-2025-2988: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6.2.0.4, and 6.2.1.0 could disclose sensitive server information to an unauthorized user that could aid in further attacks against the system.
nvd
CVE-2013-5409P3MEDIUMCVSS 6.5v5.22013-12-21
CVE-2013-5409 [MEDIUM] CWE-89 CVE-2013-5409: Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2022-22337P4MEDIUMCVSS 6.5≥ 6.0.0.0, < 6.0.3.7≥ 6.1.0.0, < 6.1.0.6+2 more2023-01-04
CVE-2022-22337 [MEDIUM] CWE-200 CVE-2022-22337: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 could disclose sensitive inform
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 could disclose sensitive information to an authenticated user. IBM X-Force ID: 219507.
nvd
CVE-2015-7410P4HIGHCVSS 7.4v5.22016-01-01
CVE-2015-7410 [HIGH] CWE-17 CVE-2015-7410: The Health Check tool in IBM Sterling B2B Integrator 5.2 does not properly use cookies in conjunctio
The Health Check tool in IBM Sterling B2B Integrator 5.2 does not properly use cookies in conjunction with HTTPS sessions, which allows man-in-the-middle attackers to obtain sensitive information or modify data via unspecified vectors.
nvd
CVE-2012-5766P4MEDIUMCVSS 6.5v5.1v5.22013-07-03
CVE-2012-5766 [MEDIUM] CWE-89 CVE-2012-5766: Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to execute arbitrary SQL commands via vectors involving the RNVisibility page and unspecified screens, a different vulnerability than CVE-2013-0560.
nvd
CVE-2013-0560P4MEDIUMCVSS 6.5v5.1v5.22013-07-03
CVE-2013-0560 [MEDIUM] CVE-2013-0560: Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2012-5766.
nvd
CVE-2019-4738P4MEDIUMCVSS 6.5≥ 5.2.0.0, ≤ 5.2.6.5≥ 6.0.0.0, ≤ 6.0.3.1+4 more2020-12-10
CVE-2019-4738 [MEDIUM] CWE-312 CVE-2019-4738: IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.1 dis
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.1 discloses sensitive information to an authenticated user from the dashboard UI which could be used in further attacks against the system. IBM X-Force ID: 172753.
nvd
CVE-2026-3482P4MEDIUMCVSS 5.3≥ 6.2.0.0, ≤ 6.2.0.5_2≥ 6.2.1.0, ≤ 6.2.1.1_2+1 more2026-07-22
CVE-2026-3482 [MEDIUM] CWE-639 CVE-2026-3482: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 throug
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 could allow an unauthenticated user to read sensitive information by bypassing authentication through a specially crafted HTTP request.
nvd
CVE-2016-9982P4MEDIUMCVSS 6.5v5.2v5.2.1+5 more2017-06-22
CVE-2016-9982 [MEDIUM] CWE-200 CVE-2016-9982: IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensiti
IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information such as account lists due to improper access control. IBM X-Force ID: 120274.
nvd
CVE-2020-4671P4MEDIUMCVSS 6.5≥ 5.2.0.0, ≤ 5.2.6.5≥ 6.0.0.0, ≤ 6.0.3.2+4 more2020-11-16
CVE-2020-4671 [MEDIUM] CWE-532 CVE-2020-4671: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 sto
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 stores potentially sensitive information in log files that could be read by an authenticatedl user. IBM X-Force ID: 186284.
nvd
CVE-2020-4566P4MEDIUMCVSS 6.5≥ 5.2.6.0, ≤ 5.2.6.5≥ 6.0.0.0, ≤ 6.0.3.2+4 more2020-11-16
CVE-2020-4566 [MEDIUM] CVE-2020-4566: IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2 sto
IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2 stores potentially highly sensitive information in log files that could be read by an authenticated user. IBM X-Force ID: 184083.
nvd
CVE-2021-20375P4MEDIUMCVSS 6.5≥ 2.2.0.0, ≤ 5.2.6.5_3≥ 6.0.0.0, ≤ 6.0.3.4+1 more2021-10-07
CVE-2021-20375 [MEDIUM] CVE-2021-20375: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to intercept and
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to intercept and replace a message sent by another user due to improper access controls. IBM X-Force ID: 195567.
nvd
CVE-2021-39087P4MEDIUMCVSS 6.5≥ 6.0.0.0, < 6.0.3.6≥ 6.1.0.0, < 6.1.0.5+7 more2022-08-16
CVE-2021-39087 [MEDIUM] CWE-276 CVE-2021-39087: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow an authenticated user to obtain sensitive information due to improper permission controls. IBM X-Force ID: 216109.
nvd
CVE-2023-22876P4MEDIUMCVSS 6.5≥ 6.0.0.0, < 6.0.3.8≥ 6.1.0.0, < 6.1.2.2+2 more2023-03-15
CVE-2023-22876 [MEDIUM] CWE-200 CVE-2023-22876: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.1 cou
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.1 could allow a privileged user to obtain sensitive information that could aid in further attacks against the system. IBM X-Force ID: 244364.
nvd
CVE-2022-22371P4MEDIUMCVSS 6.5≥ 6.0.0.0, ≤ 6.0.3.6≥ 6.1.0.0, ≤ 6.1.0.5+2 more2023-01-05
CVE-2022-22371 [MEDIUM] CWE-613 CVE-2022-22371: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 does not invalidate session aft
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 221195.
nvd
CVE-2017-1131P4MEDIUMCVSS 6.5v5.2v5.2.1+5 more2017-06-23
CVE-2017-1131 [MEDIUM] CWE-200 CVE-2017-1131: IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensiti
IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information by using unsupported, specially crafted HTTP commands. IBM X-Force ID: 121375.
nvd
CVE-2017-1193P4MEDIUMCVSS 6.5v5.2v5.2.1+5 more2017-06-23
CVE-2017-1193 [MEDIUM] CWE-200 CVE-2017-1193: IBM Sterling B2B Integrator Standard Edition 5.2 could allow user to obtain sensitive information us
IBM Sterling B2B Integrator Standard Edition 5.2 could allow user to obtain sensitive information using an HTTP GET request. IBM X-Force ID: 123667.
nvd
CVE-2021-39033P4MEDIUMCVSS 6.5≥ 6.0.0.0, < 6.0.3.6≥ 6.1.0.0, < 6.1.1.1+4 more2022-04-19
CVE-2021-39033 [MEDIUM] CWE-209 CVE-2021-39033: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 cou
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 213963.
nvd