Ibm Sterling B2B Integrator vulnerabilities
206 known vulnerabilities affecting ibm/sterling_b2b_integrator.
Total CVEs
206
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH30MEDIUM161LOW8
Vulnerabilities
Page 4 of 11
CVE-2017-1193P4MEDIUMCVSS 6.5v5.2v5.2.1+5 more2017-06-23
CVE-2017-1193 [MEDIUM] CWE-200 CVE-2017-1193: IBM Sterling B2B Integrator Standard Edition 5.2 could allow user to obtain sensitive information us
IBM Sterling B2B Integrator Standard Edition 5.2 could allow user to obtain sensitive information using an HTTP GET request. IBM X-Force ID: 123667.
nvd
CVE-2021-39033P4MEDIUMCVSS 6.5≥ 6.0.0.0, < 6.0.3.6≥ 6.1.0.0, < 6.1.1.1+4 more2022-04-19
CVE-2021-39033 [MEDIUM] CWE-209 CVE-2021-39033: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 cou
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 213963.
nvd
CVE-2020-4692P4MEDIUMCVSS 6.5≥ 5.2.0.0, ≤ 5.2.6.5≥ 6.0.0.0, ≤ 6.0.3.2+4 more2020-11-16
CVE-2020-4692 [MEDIUM] CVE-2020-4692: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 cou
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 could allow an authenticated user to obtain sensitive information from the Dashboard UI. IBM X-Force ID: 186780.
nvd
CVE-2021-20375P4MEDIUMCVSS 6.5≥ 2.2.0.0, ≤ 5.2.6.5_3≥ 6.0.0.0, ≤ 6.0.3.4+1 more2021-10-07
CVE-2021-20375 [MEDIUM] CVE-2021-20375: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to intercept and
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to intercept and replace a message sent by another user due to improper access controls. IBM X-Force ID: 195567.
nvd
CVE-2024-31914P4MEDIUMCVSS 6.4≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2, ≤ 6.2.0.22025-01-06
CVE-2024-31914 [MEDIUM] CWE-79 CVE-2024-31914: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2020-4475P4MEDIUMCVSS 6.5≥ 5.2.0.0, ≤ 5.2.6.5≥ 6.0.0.0, ≤ 6.0.3.2+4 more2020-11-16
CVE-2020-4475 [MEDIUM] CVE-2020-4475: IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2 cou
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
nvd
CVE-2013-2982P4MEDIUMCVSS 6.5v5.1v5.22013-07-03
CVE-2013-2982 [MEDIUM] CVE-2013-2982: IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authentic
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to upload arbitrary files via unspecified vectors.
nvd
CVE-2022-22482P4MEDIUMCVSS 6.5≥ 6.0.0.0, ≤ 6.0.3.5≥ 6.1.0.0, ≤ 6.1.1.0+4 more2022-05-17
CVE-2022-22482 [MEDIUM] CWE-434 CVE-2022-22482: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 cou
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow an authenticated user to upload files that could fill up the filesystem and cause a denial of service. IBM X-Force ID: 225977.
nvd
CVE-2023-32341P4MEDIUMCVSS 6.5≥ 6.0.0.0, ≤ 6.0.3.8≥ 6.1.0.0, ≤ 6.1.2.32024-02-09
CVE-2023-32341 [MEDIUM] CWE-400 CVE-2023-32341: IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 could allow an authe
IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 255827.
nvd
CVE-2013-5413P4MEDIUMCVSS 4.3v5.22013-12-21
CVE-2013-5413 [MEDIUM] CWE-287 CVE-2013-5413: IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not invalidate a session upon a log
IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not invalidate a session upon a logout action, which allows remote attackers to bypass authentication by leveraging an unattended workstation.
nvd
CVE-2013-2984P4MEDIUMCVSS 6.5v5.1v5.22013-07-03
CVE-2013-2984 [MEDIUM] CWE-22 CVE-2013-2984: Directory traversal vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gatew
Directory traversal vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote authenticated users to read or modify files via unspecified vectors.
nvd
CVE-2025-33014P4MEDIUMCVSS 6.1≥ 6.0.0.0, < 6.1.2.7_1≥ 6.2, < 6.2.0.5+2 more2025-07-18
CVE-2025-33014 [MEDIUM] CWE-1022 CVE-2025-33014: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 throug
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.4 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser.
nvd
CVE-2016-0210P4MEDIUMCVSS 5.3v5.1v5.22017-02-08
CVE-2016-0210 [MEDIUM] CWE-200 CVE-2016-0210: IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to obtain sensitive infor
IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to obtain sensitive information. By allowing HTTP OPTIONS method, a remote attacker could send a specially-crafted query to a vulnerable server running to cause the server to disclose sensitive information in the HTTP response.
nvd
CVE-2016-9983P4MEDIUMCVSS 5.3v5.2v5.2.1+5 more2017-06-22
CVE-2016-9983 [MEDIUM] CWE-200 CVE-2016-9983: IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user with special priv
IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user with special privileges to view files that they should not have access to. IBM X-Force ID: 120275.
nvd
CVE-2016-5890P4MEDIUMCVSS 5.3v5.22016-11-30
CVE-2016-5890 [MEDIUM] CWE-255 CVE-2016-5890: IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote authenti
IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote authenticated users to change arbitrary passwords via unspecified vectors.
nvd
CVE-2025-36298P4MEDIUMCVSS 5.4≥ 6.1.2.0, ≤ 6.1.2.7_2≥ 6.2.0.0, ≤ 6.2.0.5_2+2 more2026-07-30
CVE-2025-36298 [MEDIUM] CWE-79 CVE-2025-36298: IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.
IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 Ebics server component is vulnerable to cross-site scripting. This vulne
nvd
CVE-2025-36112P4MEDIUMCVSS 5.3≥ 6.0.0.0, < 6.1.2.7_2≥ 6.2.0.0, < 6.2.0.5_1+3 more2025-11-24
CVE-2025-36112 [MEDIUM] CWE-497 CVE-2025-36112: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 throug
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could reveal sensitive server IP configuration information to an unauthorized user.
nvd
CVE-2013-0476P4MEDIUMCVSS 6.4v5.1v5.22013-07-03
CVE-2013-0476 [MEDIUM] CVE-2013-0476: IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to inject arbitrary FTP commands via unspecified vectors.
nvd
CVE-2019-4063P4MEDIUMCVSS 5.9≥ 5.2.0.1, ≤ 6.0.0.0v5.2.0.1+1 more2019-03-05
CVE-2019-4063 [MEDIUM] CWE-319 CVE-2019-4063: IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 Standard Edition could allow highly sensitive in
IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 Standard Edition could allow highly sensitive information to be transmitted in plain text. An attacker could obtain this information using man in the middle techniques. IBM X-ForceID: 157008.
nvd
CVE-2018-1679P4MEDIUMCVSS 5.3≥ 5.2.0.1, ≤ 5.2.6.3v5.2+6 more2018-07-20
CVE-2018-1679 [MEDIUM] CWE-200 CVE-2018-1679: IBM Sterling B2B Integrator Standard Edition 5.2 through 5.2.6 could allow an unauthenticated user t
IBM Sterling B2B Integrator Standard Edition 5.2 through 5.2.6 could allow an unauthenticated user to obtain sensitive information that could be used in further attacks against the system. IBM X-Force ID: 145180.
nvd