Ibm Sterling B2B Integrator vulnerabilities
197 known vulnerabilities affecting ibm/sterling_b2b_integrator.
Total CVEs
197
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH29MEDIUM153LOW8
Vulnerabilities
Page 8 of 10
CVE-2017-1496P4MEDIUMCVSS 5.4v5.2v5.2.1+5 more2017-07-31
CVE-2017-1496 [MEDIUM] CWE-79 CVE-2017-1496: IBM Sterling B2B Integrator Standard Edition 5.2.x is vulnerable to cross-site scripting. This vulne
IBM Sterling B2B Integrator Standard Edition 5.2.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128694.
nvd
CVE-2023-25682P4MEDIUMCVSS 5.5≥ 6.0.0.0, < 6.0.3.9≥ 6.1.0.0, < 6.1.2.32023-11-22
CVE-2023-25682 [MEDIUM] CWE-532 CVE-2023-25682: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 sto
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 247034.
nvd
CVE-2013-0494P4MEDIUMCVSS 5.0v5.0v5.12013-08-09
CVE-2013-0494 [MEDIUM] CWE-399 CVE-2013-0494: IBM Sterling B2B Integrator 5.0 and 5.1 allows remote attackers to cause a denial of service (memory
IBM Sterling B2B Integrator 5.0 and 5.1 allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted HTTP (1) Range or (2) Request-Range header.
nvd
CVE-2016-5893P4MEDIUMCVSS 5.5v5.2v5.2.1+5 more2017-06-23
CVE-2016-5893 [MEDIUM] CWE-200 CVE-2016-5893: IBM Sterling B2B Integrator Standard Edition 5.2 allows web pages to be stored locally which can be
IBM Sterling B2B Integrator Standard Edition 5.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 115336.
nvd
CVE-2017-1349P4MEDIUMCVSS 5.5v5.2v5.2.1+5 more2017-06-23
CVE-2017-1349 [MEDIUM] CWE-200 CVE-2017-1349: IBM Sterling B2B Integrator Standard Edition 5.2 stores potentially sensitive information from HTTP
IBM Sterling B2B Integrator Standard Edition 5.2 stores potentially sensitive information from HTTP sessions that could be read by a local user. IBM X-Force ID: 126525.
nvd
CVE-2017-1302P4MEDIUMCVSS 5.5v5.2v5.2.1+5 more2017-06-23
CVE-2017-1302 [MEDIUM] CWE-200 CVE-2017-1302: IBM Sterling B2B Integrator Standard Edition 5.2 could allow a local user view sensitive information
IBM Sterling B2B Integrator Standard Edition 5.2 could allow a local user view sensitive information due to improper access controls. IBM X-Force ID: 125456.
nvd
CVE-2014-6099P4MEDIUMCVSS 5.0v5.2v5.2.42014-10-26
CVE-2014-6099 [MEDIUM] CWE-255 CVE-2014-6099: The Change Password feature in IBM Sterling B2B Integrator 5.2.x through 5.2.4 does not have a locko
The Change Password feature in IBM Sterling B2B Integrator 5.2.x through 5.2.4 does not have a lockout protection mechanism for invalid login requests, which makes it easier for remote attackers to obtain admin access via a brute-force approach.
nvd
CVE-2017-1633P4MEDIUMCVSS 4.3≥ 5.2.0.1, ≤ 5.2.6.3v5.2+6 more2018-07-20
CVE-2017-1633 [MEDIUM] CWE-200 CVE-2017-1633: IBM Sterling B2B Integrator 5.2 through 5.2.6 could allow an authenticated attacker to obtain sensit
IBM Sterling B2B Integrator 5.2 through 5.2.6 could allow an authenticated attacker to obtain sensitive variable name information using specially crafted HTTP requests. IBM X-Force ID: 133180.
nvd
CVE-2012-5936P4MEDIUMCVSS 5.0v5.1v5.22013-07-03
CVE-2012-5936 [MEDIUM] CWE-310 CVE-2012-5936: IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not set the secure
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
nvd
CVE-2013-5407P4MEDIUMCVSS 4.9v5.22013-12-21
CVE-2013-5407 [MEDIUM] CWE-20 CVE-2013-5407: IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not properly restrict use of FRAME
IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not properly restrict use of FRAME elements, which allows remote authenticated users to bypass intended access restrictions or obtain sensitive information via a crafted web site, related to a "frame injection" issue.
nvd
CVE-2020-4646P4MEDIUMCVSS 4.3≥ 5.2.0.0, ≤ 5.2.6.5≥ 6.0.0.0, ≤ 6.0.3.3+7 more2021-05-19
CVE-2020-4646 [MEDIUM] CVE-2020-4646: IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5, 6.0.0.0 through 6.0.3.3, and 6
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5, 6.0.0.0 through 6.0.3.3, and 6.1.0.0 through 6.1.0.2 could allow an authenticated user to view pages they shoiuld not have access to due to improper authorization control.
nvd
CVE-2015-7437P4MEDIUMCVSS 5.5v5.22016-01-02
CVE-2015-7437 [MEDIUM] CWE-200 CVE-2015-7437: Queue Watcher in IBM Sterling B2B Integrator 5.2 allows local users to obtain sensitive information
Queue Watcher in IBM Sterling B2B Integrator 5.2 allows local users to obtain sensitive information via unspecified vectors.
nvd
CVE-2024-56338P4MEDIUMCVSS 4.8≥ 6.0.0.0, ≤ 6.1.2.6 ≥ 6.2, ≤ 6.2.0.3 2025-03-11
CVE-2024-56338 [MEDIUM] CWE-79 CVE-2024-56338: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 is
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2025-1349P4MEDIUMCVSS 4.8≥ 6.0.0.0, < 6.1.2.7≥ 6.2, < 6.2.0.5+2 more2025-06-18
CVE-2025-1349 [MEDIUM] CWE-79 CVE-2025-1349: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 throug
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4
is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted
nvd
CVE-2025-2694P4MEDIUMCVSS 4.8≥ 6.0.0.0, < 6.1.2.7_2≥ 6.2.0.0, < 6.2.0.5+2 more2025-09-04
CVE-2025-2694 [MEDIUM] CWE-79 CVE-2025-2694: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling F
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lea
nvd
CVE-2019-4377P4MEDIUMCVSS 4.3≥ 5.2.0.0, ≤ 6.0.0.1v6.0.0.0+1 more2019-06-25
CVE-2019-4377 [MEDIUM] CWE-209 CVE-2019-4377: IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 reveals sensitive information from a stack trace tha
IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 reveals sensitive information from a stack trace that could be used in further attacks against the system. IBM X-Force ID: 162803.
nvd
CVE-2019-4222P4MEDIUMCVSS 4.3v6.0.0.0v6.0.0.12019-04-25
CVE-2019-4222 [MEDIUM] CWE-269 CVE-2019-4222: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 could allow an authenticated user t
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 could allow an authenticated user to view process definition of a business process without permission. IBM X-Force ID: 159231.
nvd
CVE-2021-29700P4MEDIUMCVSS 4.3≥ 5.2.0.0, ≤ 5.2.6.5_4≥ 6.0.0.0, ≤ 6.0.0.6+10 more2021-10-07
CVE-2021-29700 [MEDIUM] CVE-2021-29700: IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authneticated at
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authneticated attacker to obtain sensitive information from configuration files that could aid in further attacks against the system. IBM X-Force ID: 200656.
nvd
CVE-2017-1326P4MEDIUMCVSS 4.3v5.2v5.2.1+5 more2017-06-22
CVE-2017-1326 [MEDIUM] CWE-269 CVE-2017-1326: IBM Sterling File Gateway does not properly restrict user requests based on permission level. This a
IBM Sterling File Gateway does not properly restrict user requests based on permission level. This allows for users to update data related to other users, by manipulating the parameters passed in the POST request. IBM X-Force ID: 126060.
nvd
CVE-2021-20376P4MEDIUMCVSS 4.3≥ 2.2.0.0, ≤ 5.2.6.5_3≥ 6.0.0.0, ≤ 6.0.3.4+1 more2021-10-07
CVE-2021-20376 [MEDIUM] CWE-203 CVE-2021-20376: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated attacker to enumerate
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated attacker to enumerate usernames due to there being an observable discrepancy in returned messages. IBM X-Force ID: 195568.
nvd