Ibm Sterling B2B Integrator vulnerabilities
197 known vulnerabilities affecting ibm/sterling_b2b_integrator.
Total CVEs
197
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH29MEDIUM153LOW8
Vulnerabilities
Page 7 of 10
CVE-2013-0481P4MEDIUMCVSS 5.0v5.1v5.22013-07-03
CVE-2013-0481 [MEDIUM] CWE-200 CVE-2013-0481: The console in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows
The console in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to read stack traces by triggering (1) an error or (2) an exception.
nvd
CVE-2023-50307P4MEDIUMCVSS 5.4≥ 6.0.0.0, ≤ 6.0.3.9≥ 6.1.0.0, ≤ 6.1.2.3+1 more2024-04-12
CVE-2023-50307 [MEDIUM] CWE-79 CVE-2023-50307: IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnera
IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 273338.
nvd
CVE-2023-42011P4MEDIUMCVSS 5.4v6.1v6.22024-06-27
CVE-2023-42011 [MEDIUM] CWE-1021 CVE-2023-42011: IBM Sterling B2B Integrator Standard Edition 6.1 and 6.2 does not restrict or incorrectly restricts
IBM Sterling B2B Integrator Standard Edition 6.1 and 6.2 does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with. IBM X-Force ID: 265508.
nvd
CVE-2023-50309P4MEDIUMCVSS 5.4≥ 6.0.0.0, ≤ 6.1.2.5v6.2.0.02025-01-23
CVE-2023-50309 [MEDIUM] CWE-79 CVE-2023-50309: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to stored cross-site s
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2023-32340P4MEDIUMCVSS 5.4≥ 6.0.0.0, ≤ 6.1.2.5v6.2.0.02025-01-23
CVE-2023-32340 [MEDIUM] CWE-79 CVE-2023-32340: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to cross-site scriptin
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2024-31913P4MEDIUMCVSS 5.4≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2.0.0, ≤ 6.2.0.22025-01-06
CVE-2024-31913 [MEDIUM] CWE-79 CVE-2024-31913: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2016-3057P4MEDIUMCVSS 6.1v5.22016-11-30
CVE-2016-3057 [MEDIUM] CWE-79 CVE-2016-3057: Cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.
Cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2015-7431P4MEDIUMCVSS 6.1v5.22016-01-02
CVE-2015-7431 [MEDIUM] CWE-79 CVE-2015-7431: Cross-site scripting (XSS) vulnerability in Queue Watcher in IBM Sterling B2B Integrator 5.2 allows
Cross-site scripting (XSS) vulnerability in Queue Watcher in IBM Sterling B2B Integrator 5.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2016-6020P4MEDIUMCVSS 6.1v5.2v5.2.1+6 more2017-02-01
CVE-2016-6020 [MEDIUM] CWE-601 CVE-2016-6020: IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to conduct phishing attac
IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. Th
nvd
CVE-2014-6199P4MEDIUMCVSS 5.0v5.1v5.2+6 more2015-01-10
CVE-2014-6199 [MEDIUM] CWE-399 CVE-2014-6199: The HTTP Server Adapter in IBM Sterling B2B Integrator 5.1 and 5.2.x and Sterling File Gateway 2.1 a
The HTTP Server Adapter in IBM Sterling B2B Integrator 5.1 and 5.2.x and Sterling File Gateway 2.1 and 2.2 allows remote attackers to cause a denial of service (connection-slot exhaustion) via a crafted HTTP request.
nvd
CVE-2017-1132P4MEDIUMCVSS 5.4v5.2v5.2.1+5 more2017-06-23
CVE-2017-1132 [MEDIUM] CWE-79 CVE-2017-1132: IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnera
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 121418.
nvd
CVE-2017-1348P4MEDIUMCVSS 5.4v5.2v5.2.1+5 more2017-06-23
CVE-2017-1348 [MEDIUM] CWE-79 CVE-2017-1348: IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnera
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126524.
nvd
CVE-2017-1482P4MEDIUMCVSS 5.4v5.22017-12-07
CVE-2017-1482 [MEDIUM] CWE-79 CVE-2017-1482: IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnera
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128620.
nvd
CVE-2019-4073P4MEDIUMCVSS 5.4v6.0.0.0v6.0.0.12019-04-25
CVE-2019-4073 [MEDIUM] CWE-79 CVE-2019-4073: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripti
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 157107.
nvd
CVE-2019-4074P4MEDIUMCVSS 5.4v6.0.0.0v6.0.0.12019-04-25
CVE-2019-4074 [MEDIUM] CWE-79 CVE-2019-4074: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripti
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 157108.
nvd
CVE-2019-4075P4MEDIUMCVSS 5.4v6.0.0.0v6.0.0.12019-04-25
CVE-2019-4075 [MEDIUM] CWE-79 CVE-2019-4075: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripti
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 157109.
nvd
CVE-2019-4077P4MEDIUMCVSS 5.4v6.0.0.0v6.0.0.12019-04-25
CVE-2019-4077 [MEDIUM] CWE-79 CVE-2019-4077: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripti
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 157111.
nvd
CVE-2019-4076P4MEDIUMCVSS 5.4v6.0.0.0v6.0.0.12019-04-25
CVE-2019-4076 [MEDIUM] CWE-79 CVE-2019-4076: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripti
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 157110.
nvd
CVE-2019-4148P4MEDIUMCVSS 5.4v6.0.0.0v6.0.0.12019-04-25
CVE-2019-4148 [MEDIUM] CWE-79 CVE-2019-4148: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripti
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158414.
nvd
CVE-2019-4596P4MEDIUMCVSS 5.4≥ 5.2.0.0, ≤ 5.2.6.5v5.2.0.0+1 more2020-02-26
CVE-2019-4596 [MEDIUM] CWE-79 CVE-2019-4596: IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site scr
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 167879.
nvd