Ibm Sterling B2B Integrator vulnerabilities
206 known vulnerabilities affecting ibm/sterling_b2b_integrator.
Total CVEs
206
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH30MEDIUM161LOW8
Vulnerabilities
Page 5 of 11
CVE-2025-36002P4MEDIUMCVSS 5.5≥ 6.2.0.0, < 6.2.0.5_1v6.2.1.0+1 more2025-10-16
CVE-2025-36002 [MEDIUM] CWE-260 CVE-2025-36002: IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5, and 6.2.1.0 stores user credentials in configuration files which can be read by a local user.
nvd
CVE-2021-38928P4MEDIUMCVSS 5.4≥ 6.0.0.0, < 6.0.3.7≥ 6.1.0.0, < 6.1.0.6+2 more2023-01-04
CVE-2021-38928 [MEDIUM] CVE-2021-38928: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 uses Cross-Origin Resource Shar
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Force ID: 210323.
nvd
CVE-2025-36431P4MEDIUMCVSS 5.4≥ 6.2.2.0, ≤ 6.2.2.0_12026-07-30
CVE-2025-36431 [MEDIUM] CWE-79 CVE-2025-36431: IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through
IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through 6.2.2.0_1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted ses
nvd
CVE-2026-0835P4MEDIUMCVSS 5.4≥ 6.1.0.0, < 6.1.2.8≥ 6.2.0.0, < 6.2.0.5_2+5 more2026-03-13
CVE-2026-0835 [MEDIUM] CWE-79 CVE-2026-0835: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 are vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cr
nvd
CVE-2025-14504P4MEDIUMCVSS 5.4≥ 6.1.0.0, < 6.1.2.8≥ 6.2.0.0, < 6.2.0.5_2+5 more2026-03-13
CVE-2025-14504 [MEDIUM] CWE-79 CVE-2025-14504: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c
nvd
CVE-2024-27263P4MEDIUMCVSS 5.3≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2.0.0, ≤ 6.2.0.12025-01-28
CVE-2024-27263 [MEDIUM] CWE-300 CVE-2024-27263: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authe
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to obtain sensitive information from the dashboard UI using man in the middle techniques.
nvd
CVE-2025-36348P4MEDIUMCVSS 4.9≥ 6.1.0.0, < 6.1.2.8≥ 6.2.0.0, < 6.2.0.5_1+4 more2026-02-17
CVE-2025-36348 [MEDIUM] CWE-209 CVE-2025-36348: IBM Sterling B2B Integrator versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0
IBM Sterling B2B Integrator versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1, and IBM Sterling File Gateway versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1 may expose sensitive information to a remote privileged attacker due to the application returning detailed technic
nvd
CVE-2025-33008P4MEDIUMCVSS 5.4v6.2.1.02025-08-19
CVE-2025-33008 [MEDIUM] CWE-79 CVE-2025-33008: IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File Gateway 6.2.1.0 is vulnerable to cross-sit
IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File Gateway 6.2.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2023-40693P4MEDIUMCVSS 5.4≥ 6.1.0.0, < 6.1.2.8≥ 6.2.0.0, < 6.2.0.5_2+4 more2026-03-13
CVE-2023-40693 [MEDIUM] CWE-79 CVE-2023-40693: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, and 6.2.0.0 thr
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, and 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wi
nvd
CVE-2024-54183P4MEDIUMCVSS 5.4≥ 6.0.0.0, < 6.1.2.7≥ 6.2, < 6.2.0.5+2 more2025-06-18
CVE-2024-54183 [MEDIUM] CWE-79 CVE-2024-54183: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 throug
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted se
nvd
CVE-2025-2793P4MEDIUMCVSS 5.4≥ 6.0.0.0, < 6.1.2.7_1≥ 6.2, < 6.2.0.5+2 more2025-07-08
CVE-2025-2793 [MEDIUM] CWE-79 CVE-2025-2793: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gate
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway
6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4
is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadi
nvd
CVE-2025-36135P4MEDIUMCVSS 5.4≥ 6.0.0.0, ≤ 6.1.2.7_1≥ 6.2.0.0, ≤ 6.2.0.5+1 more2025-11-07
CVE-2025-36135 [MEDIUM] CWE-79 CVE-2025-36135: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended func
nvd
CVE-2026-1918P4MEDIUMCVSS 4.9≥ 6.2.0.0, ≤ 6.2.0.5_2≥ 6.2.1.0, ≤ 6.2.1.1_2+1 more2026-07-28
CVE-2026-1918 [MEDIUM] CWE-532 CVE-2026-1918: IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 throug
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 stores potentially sensitive information in log files that could be read by a privileged user.
nvd
CVE-2018-1564P4MEDIUMCVSS 6.7≥ 5.2.0.1, ≤ 5.2.6.3v5.2+6 more2018-07-20
CVE-2018-1564 [MEDIUM] CWE-200 CVE-2018-1564: IBM Sterling B2B Integrator Standard Edition 5.2 through 5.2.6 could allow a local user with adminis
IBM Sterling B2B Integrator Standard Edition 5.2 through 5.2.6 could allow a local user with administrator privileges to obtain user passwords found in debugging messages. IBM X-Force ID: 142968.
nvd
CVE-2020-4657P4MEDIUMCVSS 6.1≥ 5.2.0.0, ≤ 6.0.3.2v5.2.0.0+1 more2020-12-16
CVE-2020-4657 [MEDIUM] CWE-79 CVE-2020-4657: IBM Sterling B2B Integrator 5.2.0.0 through 6.0.3.2 Standard Edition is vulnerable to cross-site scr
IBM Sterling B2B Integrator 5.2.0.0 through 6.0.3.2 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186094.
nvd
CVE-2021-20561P4MEDIUMCVSS 6.1≥ 2.2.0.0, ≤ 5.2.6.5_4≥ 6.0.0.0, ≤ 6.0.0.6+2 more2021-10-07
CVE-2021-20561 [MEDIUM] CWE-79 CVE-2021-20561: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulner
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199230.
nvd
CVE-2014-0912P4MEDIUMCVSS 5.3v5.1v5.22018-04-20
CVE-2014-0912 [MEDIUM] CWE-200 CVE-2014-0912: IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to obtain sensitive product information via vectors related to an error page. IBM X-Force ID: 92072.
nvd
CVE-2015-5019P4MEDIUMCVSS 5.5v5.22015-11-08
CVE-2015-5019 [MEDIUM] CWE-264 CVE-2015-5019: IBM Sterling Integrator 5.1 before 5010004_8 and Sterling B2B Integrator 5.2 before 5020500_9 allow
IBM Sterling Integrator 5.1 before 5010004_8 and Sterling B2B Integrator 5.2 before 5020500_9 allow remote authenticated users to read or upload files by leveraging a password-change requirement.
nvd
CVE-2023-45186P4MEDIUMCVSS 5.4≥ 6.0.0.0, ≤ 6.0.3.9≥ 6.1.0.0, ≤ 6.1.2.3+1 more2024-04-12
CVE-2023-45186 [MEDIUM] CWE-79 CVE-2023-45186: IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnera
IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 2
nvd
CVE-2021-20553P4MEDIUMCVSS 5.4≥ 5.2.0.0, ≤ 6.1.1.0≥ 6.0.0.0, ≤ 6.0.0.6+2 more2024-12-19
CVE-2021-20553 [MEDIUM] CWE-79 CVE-2021-20553: IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site scr
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd