Ibm Sterling B2B Integrator vulnerabilities
206 known vulnerabilities affecting ibm/sterling_b2b_integrator.
Total CVEs
206
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH30MEDIUM161LOW8
Vulnerabilities
Page 3 of 11
CVE-2021-29837P3HIGHCVSS 8.8≥ 5.2.0.0, ≤ 6.0.3.4≥ 6.1.0.0, ≤ 6.1.0.3+4 more2021-10-06
CVE-2021-29837 [HIGH] CWE-352 CVE-2021-29837: IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site req
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 204913.
nvd
CVE-2018-1720P3HIGHCVSS 7.5v5.2.0.1v5.2.6.3_6+2 more2019-04-25
CVE-2018-1720 [HIGH] CWE-327 CVE-2018-1720: IBM Sterling B2B Integrator Standard Edition 5.2.0.1, 5.2.6.3_6, 6.0.0.0, and 6.0.0.1 uses weaker th
IBM Sterling B2B Integrator Standard Edition 5.2.0.1, 5.2.6.3_6, 6.0.0.0, and 6.0.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 147294.
nvd
CVE-2026-7362P3MEDIUMCVSS 6.5≥ 6.2.1.0, ≤ 6.2.1.1_2≥ 6.2.2.0, ≤ 6.2.2.0_12026-07-28
CVE-2026-7362 [MEDIUM] CWE-284 CVE-2026-7362: IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterlin
IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 could allow an authenticated user to obtain sensitive information that should only be available to a privileged user.
nvd
CVE-2025-14483P3MEDIUMCVSS 6.5≥ 6.1.0.0, < 6.1.2.8≥ 6.2.0.0, < 6.2.0.5_2+5 more2026-03-13
CVE-2025-14483 [MEDIUM] CWE-201 CVE-2025-14483: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 could disclose sensitive host information to authenticated users in responses that could be used in further attacks against the system.
nvd
CVE-2025-2988P3MEDIUMCVSS 6.5≥ 6.0.0.0, < 6.1.2.7_1≥ 6.2.0.0, < 6.2.0.5+3 more2025-08-19
CVE-2025-2988 [MEDIUM] CWE-497 CVE-2025-2988: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6.2.0.4, and 6.2.1.0 could disclose sensitive server information to an unauthorized user that could aid in further attacks against the system.
nvd
CVE-2013-5409P4MEDIUMCVSS 6.5v5.22013-12-21
CVE-2013-5409 [MEDIUM] CWE-89 CVE-2013-5409: Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2022-22337P4MEDIUMCVSS 6.5≥ 6.0.0.0, < 6.0.3.7≥ 6.1.0.0, < 6.1.0.6+2 more2023-01-04
CVE-2022-22337 [MEDIUM] CWE-200 CVE-2022-22337: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 could disclose sensitive inform
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 could disclose sensitive information to an authenticated user. IBM X-Force ID: 219507.
nvd
CVE-2026-19273P3MEDIUMCVSS 5.4≥ 6.2.0.0, ≤ 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.12026-09-14
CVE-2026-19273 [MEDIUM] CWE-287 CVE-2026-19273: IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 and IBM
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 Standard Edition could allow a remote authenticated attacker to bypass security restrictions due to improper authentication.
nvd
CVE-2015-7410P4HIGHCVSS 7.4v5.22016-01-01
CVE-2015-7410 [HIGH] CWE-17 CVE-2015-7410: The Health Check tool in IBM Sterling B2B Integrator 5.2 does not properly use cookies in conjunctio
The Health Check tool in IBM Sterling B2B Integrator 5.2 does not properly use cookies in conjunction with HTTPS sessions, which allows man-in-the-middle attackers to obtain sensitive information or modify data via unspecified vectors.
nvd
CVE-2012-5766P4MEDIUMCVSS 6.5v5.1v5.22013-07-03
CVE-2012-5766 [MEDIUM] CWE-89 CVE-2012-5766: Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to execute arbitrary SQL commands via vectors involving the RNVisibility page and unspecified screens, a different vulnerability than CVE-2013-0560.
nvd
CVE-2021-39087P4MEDIUMCVSS 6.5≥ 6.0.0.0, < 6.0.3.6≥ 6.1.0.0, < 6.1.0.5+7 more2022-08-16
CVE-2021-39087 [MEDIUM] CWE-276 CVE-2021-39087: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow an authenticated user to obtain sensitive information due to improper permission controls. IBM X-Force ID: 216109.
nvd
CVE-2019-4738P4MEDIUMCVSS 6.5≥ 5.2.0.0, ≤ 5.2.6.5≥ 6.0.0.0, ≤ 6.0.3.1+4 more2020-12-10
CVE-2019-4738 [MEDIUM] CWE-312 CVE-2019-4738: IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.1 dis
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.1 discloses sensitive information to an authenticated user from the dashboard UI which could be used in further attacks against the system. IBM X-Force ID: 172753.
nvd
CVE-2026-3482P4MEDIUMCVSS 5.3≥ 6.2.0.0, ≤ 6.2.0.5_2≥ 6.2.1.0, ≤ 6.2.1.1_2+1 more2026-07-22
CVE-2026-3482 [MEDIUM] CWE-639 CVE-2026-3482: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 throug
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 could allow an unauthenticated user to read sensitive information by bypassing authentication through a specially crafted HTTP request.
nvd
CVE-2017-1131P4MEDIUMCVSS 6.5v5.2v5.2.1+5 more2017-06-23
CVE-2017-1131 [MEDIUM] CWE-200 CVE-2017-1131: IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensiti
IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information by using unsupported, specially crafted HTTP commands. IBM X-Force ID: 121375.
nvd
CVE-2016-9982P4MEDIUMCVSS 6.5v5.2v5.2.1+5 more2017-06-22
CVE-2016-9982 [MEDIUM] CWE-200 CVE-2016-9982: IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensiti
IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information such as account lists due to improper access control. IBM X-Force ID: 120274.
nvd
CVE-2020-4671P4MEDIUMCVSS 6.5≥ 5.2.0.0, ≤ 5.2.6.5≥ 6.0.0.0, ≤ 6.0.3.2+4 more2020-11-16
CVE-2020-4671 [MEDIUM] CWE-532 CVE-2020-4671: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 sto
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 stores potentially sensitive information in log files that could be read by an authenticatedl user. IBM X-Force ID: 186284.
nvd
CVE-2020-4566P4MEDIUMCVSS 6.5≥ 5.2.6.0, ≤ 5.2.6.5≥ 6.0.0.0, ≤ 6.0.3.2+4 more2020-11-16
CVE-2020-4566 [MEDIUM] CVE-2020-4566: IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2 sto
IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2 stores potentially highly sensitive information in log files that could be read by an authenticated user. IBM X-Force ID: 184083.
nvd
CVE-2013-0560P4MEDIUMCVSS 6.5v5.1v5.22013-07-03
CVE-2013-0560 [MEDIUM] CVE-2013-0560: Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2012-5766.
nvd
CVE-2023-22876P4MEDIUMCVSS 6.5≥ 6.0.0.0, < 6.0.3.8≥ 6.1.0.0, < 6.1.2.2+2 more2023-03-15
CVE-2023-22876 [MEDIUM] CWE-200 CVE-2023-22876: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.1 cou
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.1 could allow a privileged user to obtain sensitive information that could aid in further attacks against the system. IBM X-Force ID: 244364.
nvd
CVE-2022-22371P4MEDIUMCVSS 6.5≥ 6.0.0.0, ≤ 6.0.3.6≥ 6.1.0.0, ≤ 6.1.0.5+2 more2023-01-05
CVE-2022-22371 [MEDIUM] CWE-613 CVE-2022-22371: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 does not invalidate session aft
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 221195.
nvd