cbcvebase.

Ibm Sterling B2B Integrator vulnerabilities

206 known vulnerabilities affecting ibm/sterling_b2b_integrator.

Total CVEs
206
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH30MEDIUM161LOW8

Vulnerabilities

Page 8 of 11
CVE-2019-4077P4MEDIUMCVSS 5.4v6.0.0.0v6.0.0.12019-04-25
CVE-2019-4077 [MEDIUM] CWE-79 CVE-2019-4077: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripti IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 157111.
nvd
CVE-2019-4076P4MEDIUMCVSS 5.4v6.0.0.0v6.0.0.12019-04-25
CVE-2019-4076 [MEDIUM] CWE-79 CVE-2019-4076: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripti IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 157110.
nvd
CVE-2019-4148P4MEDIUMCVSS 5.4v6.0.0.0v6.0.0.12019-04-25
CVE-2019-4148 [MEDIUM] CWE-79 CVE-2019-4148: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripti IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158414.
nvd
CVE-2019-4596P4MEDIUMCVSS 5.4≥ 5.2.0.0, ≤ 5.2.6.5v5.2.0.0+1 more2020-02-26
CVE-2019-4596 [MEDIUM] CWE-79 CVE-2019-4596: IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site scr IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 167879.
nvd
CVE-2017-1496P4MEDIUMCVSS 5.4v5.2v5.2.1+5 more2017-07-31
CVE-2017-1496 [MEDIUM] CWE-79 CVE-2017-1496: IBM Sterling B2B Integrator Standard Edition 5.2.x is vulnerable to cross-site scripting. This vulne IBM Sterling B2B Integrator Standard Edition 5.2.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128694.
nvd
CVE-2023-25682P4MEDIUMCVSS 5.5≥ 6.0.0.0, < 6.0.3.9≥ 6.1.0.0, < 6.1.2.32023-11-22
CVE-2023-25682 [MEDIUM] CWE-532 CVE-2023-25682: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 sto IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 247034.
nvd
CVE-2013-0481P4MEDIUMCVSS 5.0v5.1v5.22013-07-03
CVE-2013-0481 [MEDIUM] CWE-200 CVE-2013-0481: The console in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows The console in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to read stack traces by triggering (1) an error or (2) an exception.
nvd
CVE-2023-42011P4MEDIUMCVSS 5.4v6.1v6.22024-06-27
CVE-2023-42011 [MEDIUM] CWE-1021 CVE-2023-42011: IBM Sterling B2B Integrator Standard Edition 6.1 and 6.2 does not restrict or incorrectly restricts IBM Sterling B2B Integrator Standard Edition 6.1 and 6.2 does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with. IBM X-Force ID: 265508.
nvd
CVE-2016-5893P4MEDIUMCVSS 5.5v5.2v5.2.1+5 more2017-06-23
CVE-2016-5893 [MEDIUM] CWE-200 CVE-2016-5893: IBM Sterling B2B Integrator Standard Edition 5.2 allows web pages to be stored locally which can be IBM Sterling B2B Integrator Standard Edition 5.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 115336.
nvd
CVE-2017-1349P4MEDIUMCVSS 5.5v5.2v5.2.1+5 more2017-06-23
CVE-2017-1349 [MEDIUM] CWE-200 CVE-2017-1349: IBM Sterling B2B Integrator Standard Edition 5.2 stores potentially sensitive information from HTTP IBM Sterling B2B Integrator Standard Edition 5.2 stores potentially sensitive information from HTTP sessions that could be read by a local user. IBM X-Force ID: 126525.
nvd
CVE-2017-1302P4MEDIUMCVSS 5.5v5.2v5.2.1+5 more2017-06-23
CVE-2017-1302 [MEDIUM] CWE-200 CVE-2017-1302: IBM Sterling B2B Integrator Standard Edition 5.2 could allow a local user view sensitive information IBM Sterling B2B Integrator Standard Edition 5.2 could allow a local user view sensitive information due to improper access controls. IBM X-Force ID: 125456.
nvd
CVE-2014-6099P4MEDIUMCVSS 5.0v5.2v5.2.42014-10-26
CVE-2014-6099 [MEDIUM] CWE-255 CVE-2014-6099: The Change Password feature in IBM Sterling B2B Integrator 5.2.x through 5.2.4 does not have a locko The Change Password feature in IBM Sterling B2B Integrator 5.2.x through 5.2.4 does not have a lockout protection mechanism for invalid login requests, which makes it easier for remote attackers to obtain admin access via a brute-force approach.
nvd
CVE-2017-1633P4MEDIUMCVSS 4.3≥ 5.2.0.1, ≤ 5.2.6.3v5.2+6 more2018-07-20
CVE-2017-1633 [MEDIUM] CWE-200 CVE-2017-1633: IBM Sterling B2B Integrator 5.2 through 5.2.6 could allow an authenticated attacker to obtain sensit IBM Sterling B2B Integrator 5.2 through 5.2.6 could allow an authenticated attacker to obtain sensitive variable name information using specially crafted HTTP requests. IBM X-Force ID: 133180.
nvd
CVE-2013-0494P4MEDIUMCVSS 5.0v5.0v5.12013-08-09
CVE-2013-0494 [MEDIUM] CWE-399 CVE-2013-0494: IBM Sterling B2B Integrator 5.0 and 5.1 allows remote attackers to cause a denial of service (memory IBM Sterling B2B Integrator 5.0 and 5.1 allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted HTTP (1) Range or (2) Request-Range header.
nvd
CVE-2013-5407P4MEDIUMCVSS 4.9v5.22013-12-21
CVE-2013-5407 [MEDIUM] CWE-20 CVE-2013-5407: IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not properly restrict use of FRAME IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not properly restrict use of FRAME elements, which allows remote authenticated users to bypass intended access restrictions or obtain sensitive information via a crafted web site, related to a "frame injection" issue.
nvd
CVE-2026-7775P4MEDIUMCVSS 4.8≥ 6.2.0.0, ≤ 6.2.0.6≥ 6.2.1.0, ≤ 6.2.1.1_2+1 more2026-07-28
CVE-2026-7775 [MEDIUM] CWE-79 CVE-2026-7775: IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the W
nvd
CVE-2020-4646P4MEDIUMCVSS 4.3≥ 5.2.0.0, ≤ 5.2.6.5≥ 6.0.0.0, ≤ 6.0.3.3+7 more2021-05-19
CVE-2020-4646 [MEDIUM] CVE-2020-4646: IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5, 6.0.0.0 through 6.0.3.3, and 6 IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5, 6.0.0.0 through 6.0.3.3, and 6.1.0.0 through 6.1.0.2 could allow an authenticated user to view pages they shoiuld not have access to due to improper authorization control.
nvd
CVE-2026-3157P4MEDIUMCVSS 4.3≥ 6.2.0.0, ≤ 6.2.0.5_2≥ 6.2.1.0, ≤ 6.2.1.1_2+1 more2026-07-28
CVE-2026-3157 [MEDIUM] CWE-615 CVE-2026-3157: IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 throug IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to an information disclosure due to sensitive information being included in the source code comments of a mailbox
nvd
CVE-2026-3158P4MEDIUMCVSS 4.3≥ 6.2.0.0, ≤ 6.2.0.5_2≥ 6.2.1.0, ≤ 6.2.1.1_2+1 more2026-07-28
CVE-2026-3158 [MEDIUM] CWE-615 CVE-2026-3158: IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 throug IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to an information disclosure due to sensitive information being included in the source code comments of a dashboa
nvd
CVE-2015-7437P4MEDIUMCVSS 5.5v5.22016-01-02
CVE-2015-7437 [MEDIUM] CWE-200 CVE-2015-7437: Queue Watcher in IBM Sterling B2B Integrator 5.2 allows local users to obtain sensitive information Queue Watcher in IBM Sterling B2B Integrator 5.2 allows local users to obtain sensitive information via unspecified vectors.
nvd
Ibm Sterling B2B Integrator vulnerabilities | cvebase