cbcvebase.

Ibm Sterling B2B Integrator vulnerabilities

197 known vulnerabilities affecting ibm/sterling_b2b_integrator.

Total CVEs
197
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH29MEDIUM153LOW8

Vulnerabilities

Page 4 of 10
CVE-2020-4692P4MEDIUMCVSS 6.5≥ 5.2.0.0, ≤ 5.2.6.5≥ 6.0.0.0, ≤ 6.0.3.2+4 more2020-11-16
CVE-2020-4692 [MEDIUM] CVE-2020-4692: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 cou IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 could allow an authenticated user to obtain sensitive information from the Dashboard UI. IBM X-Force ID: 186780.
nvd
CVE-2013-2982P4MEDIUMCVSS 6.5v5.1v5.22013-07-03
CVE-2013-2982 [MEDIUM] CVE-2013-2982: IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authentic IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to upload arbitrary files via unspecified vectors.
nvd
CVE-2024-31914P4MEDIUMCVSS 6.4≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2, ≤ 6.2.0.22025-01-06
CVE-2024-31914 [MEDIUM] CWE-79 CVE-2024-31914: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2013-2984P4MEDIUMCVSS 6.5v5.1v5.22013-07-03
CVE-2013-2984 [MEDIUM] CWE-22 CVE-2013-2984: Directory traversal vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gatew Directory traversal vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote authenticated users to read or modify files via unspecified vectors.
nvd
CVE-2020-4475P4MEDIUMCVSS 6.5≥ 5.2.0.0, ≤ 5.2.6.5≥ 6.0.0.0, ≤ 6.0.3.2+4 more2020-11-16
CVE-2020-4475 [MEDIUM] CVE-2020-4475: IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2 cou IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
nvd
CVE-2022-22482P4MEDIUMCVSS 6.5≥ 6.0.0.0, ≤ 6.0.3.5≥ 6.1.0.0, ≤ 6.1.1.0+4 more2022-05-17
CVE-2022-22482 [MEDIUM] CWE-434 CVE-2022-22482: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 cou IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow an authenticated user to upload files that could fill up the filesystem and cause a denial of service. IBM X-Force ID: 225977.
nvd
CVE-2023-32341P4MEDIUMCVSS 6.5≥ 6.0.0.0, ≤ 6.0.3.8≥ 6.1.0.0, ≤ 6.1.2.32024-02-09
CVE-2023-32341 [MEDIUM] CWE-400 CVE-2023-32341: IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 could allow an authe IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 255827.
nvd
CVE-2025-36112P4MEDIUMCVSS 5.3≥ 6.0.0.0, < 6.1.2.7_2≥ 6.2.0.0, < 6.2.0.5_1+3 more2025-11-24
CVE-2025-36112 [MEDIUM] CWE-497 CVE-2025-36112: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 throug IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could reveal sensitive server IP configuration information to an unauthorized user.
nvd
CVE-2013-5413P4MEDIUMCVSS 4.3v5.22013-12-21
CVE-2013-5413 [MEDIUM] CWE-287 CVE-2013-5413: IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not invalidate a session upon a log IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not invalidate a session upon a logout action, which allows remote attackers to bypass authentication by leveraging an unattended workstation.
nvd
CVE-2013-0476P4MEDIUMCVSS 6.4v5.1v5.22013-07-03
CVE-2013-0476 [MEDIUM] CVE-2013-0476: IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to inject arbitrary FTP commands via unspecified vectors.
nvd
CVE-2025-33014P4MEDIUMCVSS 6.1≥ 6.0.0.0, < 6.1.2.7_1≥ 6.2, < 6.2.0.5+2 more2025-07-18
CVE-2025-33014 [MEDIUM] CWE-1022 CVE-2025-33014: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 throug IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.4 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser.
nvd
CVE-2016-0210P4MEDIUMCVSS 5.3v5.1v5.22017-02-08
CVE-2016-0210 [MEDIUM] CWE-200 CVE-2016-0210: IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to obtain sensitive infor IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to obtain sensitive information. By allowing HTTP OPTIONS method, a remote attacker could send a specially-crafted query to a vulnerable server running to cause the server to disclose sensitive information in the HTTP response.
nvd
CVE-2016-9983P4MEDIUMCVSS 5.3v5.2v5.2.1+5 more2017-06-22
CVE-2016-9983 [MEDIUM] CWE-200 CVE-2016-9983: IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user with special priv IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user with special privileges to view files that they should not have access to. IBM X-Force ID: 120275.
nvd
CVE-2016-5890P4MEDIUMCVSS 5.3v5.22016-11-30
CVE-2016-5890 [MEDIUM] CWE-255 CVE-2016-5890: IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote authenti IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote authenticated users to change arbitrary passwords via unspecified vectors.
nvd
CVE-2025-36002P4MEDIUMCVSS 5.5≥ 6.2.0.0, < 6.2.0.5_1v6.2.1.0+1 more2025-10-16
CVE-2025-36002 [MEDIUM] CWE-260 CVE-2025-36002: IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0 IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5, and 6.2.1.0 stores user credentials in configuration files which can be read by a local user.
nvd
CVE-2019-4063P4MEDIUMCVSS 5.9≥ 5.2.0.1, ≤ 6.0.0.0v5.2.0.1+1 more2019-03-05
CVE-2019-4063 [MEDIUM] CWE-319 CVE-2019-4063: IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 Standard Edition could allow highly sensitive in IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 Standard Edition could allow highly sensitive information to be transmitted in plain text. An attacker could obtain this information using man in the middle techniques. IBM X-ForceID: 157008.
nvd
CVE-2018-1679P4MEDIUMCVSS 5.3≥ 5.2.0.1, ≤ 5.2.6.3v5.2+6 more2018-07-20
CVE-2018-1679 [MEDIUM] CWE-200 CVE-2018-1679: IBM Sterling B2B Integrator Standard Edition 5.2 through 5.2.6 could allow an unauthenticated user t IBM Sterling B2B Integrator Standard Edition 5.2 through 5.2.6 could allow an unauthenticated user to obtain sensitive information that could be used in further attacks against the system. IBM X-Force ID: 145180.
nvd
CVE-2021-38928P4MEDIUMCVSS 5.4≥ 6.0.0.0, < 6.0.3.7≥ 6.1.0.0, < 6.1.0.6+2 more2023-01-04
CVE-2021-38928 [MEDIUM] CVE-2021-38928: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 uses Cross-Origin Resource Shar IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Force ID: 210323.
nvd
CVE-2026-0835P4MEDIUMCVSS 5.4≥ 6.1.0.0, < 6.1.2.8≥ 6.2.0.0, < 6.2.0.5_2+5 more2026-03-13
CVE-2026-0835 [MEDIUM] CWE-79 CVE-2026-0835: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 are vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cr
nvd
CVE-2025-14504P4MEDIUMCVSS 5.4≥ 6.1.0.0, < 6.1.2.8≥ 6.2.0.0, < 6.2.0.5_2+5 more2026-03-13
CVE-2025-14504 [MEDIUM] CWE-79 CVE-2025-14504: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c
nvd
Ibm Sterling B2B Integrator vulnerabilities | cvebase