Ibm Sterling B2B Integrator vulnerabilities
206 known vulnerabilities affecting ibm/sterling_b2b_integrator.
Total CVEs
206
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH30MEDIUM161LOW8
Vulnerabilities
Page 7 of 11
CVE-2022-43579P4MEDIUMCVSS 5.4≥ 6.0.0.0, ≤ 6.0.3.7≥ 6.1.0.0, ≤ 6.1.2.02023-02-17
CVE-2022-43579 [MEDIUM] CWE-79 CVE-2022-43579: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 is
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 238684.
nvd
CVE-2022-22352P4MEDIUMCVSS 5.4≥ 6.0.0.0, < 6.0.3.7≥ 6.1.0.0, < 6.1.0.6+2 more2023-01-04
CVE-2022-22352 [MEDIUM] CWE-79 CVE-2022-22352: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to cross-site scr
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 220398.
nvd
CVE-2023-50307P4MEDIUMCVSS 5.4≥ 6.0.0.0, ≤ 6.0.3.9≥ 6.1.0.0, ≤ 6.1.2.3+1 more2024-04-12
CVE-2023-50307 [MEDIUM] CWE-79 CVE-2023-50307: IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnera
IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 273338.
nvd
CVE-2023-50309P4MEDIUMCVSS 5.4≥ 6.0.0.0, ≤ 6.1.2.5v6.2.0.02025-01-23
CVE-2023-50309 [MEDIUM] CWE-79 CVE-2023-50309: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to stored cross-site s
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2023-32340P4MEDIUMCVSS 5.4≥ 6.0.0.0, ≤ 6.1.2.5v6.2.0.02025-01-23
CVE-2023-32340 [MEDIUM] CWE-79 CVE-2023-32340: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to cross-site scriptin
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2024-31913P4MEDIUMCVSS 5.4≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2.0.0, ≤ 6.2.0.22025-01-06
CVE-2024-31913 [MEDIUM] CWE-79 CVE-2024-31913: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2025-2667P4MEDIUMCVSS 4.9≥ 6.0.0.0, < 6.1.2.7_2≥ 6.2.0.0, < 6.2.0.5+2 more2025-09-04
CVE-2025-2667 [MEDIUM] CWE-497 CVE-2025-2667: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling F
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 could disclose sensitive system information about the server to a privileged user that could aid in further attacks against the system.
nvd
CVE-2016-3057P4MEDIUMCVSS 6.1v5.22016-11-30
CVE-2016-3057 [MEDIUM] CWE-79 CVE-2016-3057: Cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.
Cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2015-7431P4MEDIUMCVSS 6.1v5.22016-01-02
CVE-2015-7431 [MEDIUM] CWE-79 CVE-2015-7431: Cross-site scripting (XSS) vulnerability in Queue Watcher in IBM Sterling B2B Integrator 5.2 allows
Cross-site scripting (XSS) vulnerability in Queue Watcher in IBM Sterling B2B Integrator 5.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2016-6020P4MEDIUMCVSS 6.1v5.2v5.2.1+6 more2017-02-01
CVE-2016-6020 [MEDIUM] CWE-601 CVE-2016-6020: IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to conduct phishing attac
IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. Th
nvd
CVE-2014-6199P4MEDIUMCVSS 5.0v5.1v5.2+6 more2015-01-10
CVE-2014-6199 [MEDIUM] CWE-399 CVE-2014-6199: The HTTP Server Adapter in IBM Sterling B2B Integrator 5.1 and 5.2.x and Sterling File Gateway 2.1 a
The HTTP Server Adapter in IBM Sterling B2B Integrator 5.1 and 5.2.x and Sterling File Gateway 2.1 and 2.2 allows remote attackers to cause a denial of service (connection-slot exhaustion) via a crafted HTTP request.
nvd
CVE-2019-4258P4MEDIUMCVSS 5.4v6.0.0.0v6.0.0.12019-05-01
CVE-2019-4258 [MEDIUM] CWE-79 CVE-2019-4258: IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 Standard Edition is vulnerable to cross-site scripti
IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159946.
nvd
CVE-2019-4028P4MEDIUMCVSS 5.4≥ 5.2.0.1, ≤ 6.0.0.0v5.2.0.1+1 more2019-03-05
CVE-2019-4028 [MEDIUM] CWE-79 CVE-2019-4028: IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 is vulnerable to cross-site scripting. This vuln
IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155906.
nvd
CVE-2019-4029P4MEDIUMCVSS 5.4≥ 5.2.0.1, ≤ 6.0.0.0v5.2.0.1+1 more2019-03-05
CVE-2019-4029 [MEDIUM] CWE-79 CVE-2019-4029: IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 is vulnerable to cross-site scripting. This vuln
IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 155907.
nvd
CVE-2017-1132P4MEDIUMCVSS 5.4v5.2v5.2.1+5 more2017-06-23
CVE-2017-1132 [MEDIUM] CWE-79 CVE-2017-1132: IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnera
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 121418.
nvd
CVE-2017-1348P4MEDIUMCVSS 5.4v5.2v5.2.1+5 more2017-06-23
CVE-2017-1348 [MEDIUM] CWE-79 CVE-2017-1348: IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnera
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126524.
nvd
CVE-2017-1482P4MEDIUMCVSS 5.4v5.22017-12-07
CVE-2017-1482 [MEDIUM] CWE-79 CVE-2017-1482: IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnera
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128620.
nvd
CVE-2019-4073P4MEDIUMCVSS 5.4v6.0.0.0v6.0.0.12019-04-25
CVE-2019-4073 [MEDIUM] CWE-79 CVE-2019-4073: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripti
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 157107.
nvd
CVE-2019-4074P4MEDIUMCVSS 5.4v6.0.0.0v6.0.0.12019-04-25
CVE-2019-4074 [MEDIUM] CWE-79 CVE-2019-4074: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripti
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 157108.
nvd
CVE-2019-4075P4MEDIUMCVSS 5.4v6.0.0.0v6.0.0.12019-04-25
CVE-2019-4075 [MEDIUM] CWE-79 CVE-2019-4075: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripti
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 157109.
nvd