cbcvebase.

Ibm Sterling B2B Integrator vulnerabilities

206 known vulnerabilities affecting ibm/sterling_b2b_integrator.

Total CVEs
206
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH30MEDIUM161LOW8

Vulnerabilities

Page 9 of 11
CVE-2012-5936P4MEDIUMCVSS 5.0v5.1v5.22013-07-03
CVE-2012-5936 [MEDIUM] CWE-310 CVE-2012-5936: IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not set the secure IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
nvd
CVE-2024-56338P4MEDIUMCVSS 4.8≥ 6.0.0.0, ≤ 6.1.2.6 ≥ 6.2, ≤ 6.2.0.3 2025-03-11
CVE-2024-56338 [MEDIUM] CWE-79 CVE-2024-56338: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 is IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2025-1349P4MEDIUMCVSS 4.8≥ 6.0.0.0, < 6.1.2.7≥ 6.2, < 6.2.0.5+2 more2025-06-18
CVE-2025-1349 [MEDIUM] CWE-79 CVE-2025-1349: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 throug IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted
nvd
CVE-2025-2694P4MEDIUMCVSS 4.8≥ 6.0.0.0, < 6.1.2.7_2≥ 6.2.0.0, < 6.2.0.5+2 more2025-09-04
CVE-2025-2694 [MEDIUM] CWE-79 CVE-2025-2694: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling F IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lea
nvd
CVE-2019-4222P4MEDIUMCVSS 4.3v6.0.0.0v6.0.0.12019-04-25
CVE-2019-4222 [MEDIUM] CWE-269 CVE-2019-4222: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 could allow an authenticated user t IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 could allow an authenticated user to view process definition of a business process without permission. IBM X-Force ID: 159231.
nvd
CVE-2021-29700P4MEDIUMCVSS 4.3≥ 5.2.0.0, ≤ 5.2.6.5_4≥ 6.0.0.0, ≤ 6.0.0.6+10 more2021-10-07
CVE-2021-29700 [MEDIUM] CVE-2021-29700: IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authneticated at IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authneticated attacker to obtain sensitive information from configuration files that could aid in further attacks against the system. IBM X-Force ID: 200656.
nvd
CVE-2017-1326P4MEDIUMCVSS 4.3v5.2v5.2.1+5 more2017-06-22
CVE-2017-1326 [MEDIUM] CWE-269 CVE-2017-1326: IBM Sterling File Gateway does not properly restrict user requests based on permission level. This a IBM Sterling File Gateway does not properly restrict user requests based on permission level. This allows for users to update data related to other users, by manipulating the parameters passed in the POST request. IBM X-Force ID: 126060.
nvd
CVE-2021-20376P4MEDIUMCVSS 4.3≥ 2.2.0.0, ≤ 5.2.6.5_3≥ 6.0.0.0, ≤ 6.0.3.4+1 more2021-10-07
CVE-2021-20376 [MEDIUM] CWE-203 CVE-2021-20376: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated attacker to enumerate IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated attacker to enumerate usernames due to there being an observable discrepancy in returned messages. IBM X-Force ID: 195568.
nvd
CVE-2021-29758P4MEDIUMCVSS 4.3≥ 5.2.0.0, ≤ 6.1.0.3v6.0.0.0+7 more2021-10-06
CVE-2021-29758 [MEDIUM] CVE-2021-29758: IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated us IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to perform actions that they should not be able to access due to improper access controls. IBM X-Force ID: 202169.
nvd
CVE-2021-29760P4MEDIUMCVSS 4.3≥ 5.2.0.0, ≤ 6.1.0.3v6.0.0.0+7 more2021-10-06
CVE-2021-29760 [MEDIUM] CVE-2021-29760: IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated us IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to download unauthorized files through the dashboard user interface. IBM X-Force ID: 202213.
nvd
CVE-2024-54172P4MEDIUMCVSS 4.3≥ 6.0.0.0, < 6.1.2.7≥ 6.2, < 6.2.0.5+2 more2025-06-18
CVE-2024-54172 [MEDIUM] CWE-352 CVE-2024-54172: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 throug IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
nvd
CVE-2013-0539P4MEDIUMCVSS 5.0v5.1v5.22013-07-03
CVE-2013-0539 [MEDIUM] CWE-255 CVE-2013-0539: An unspecified third-party component in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Ga An unspecified third-party component in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 uses short session ID values, which makes it easier for remote attackers to hijack sessions, and consequently obtain sensitive information, via a brute-force attack.
nvd
CVE-2020-4705P4MEDIUMCVSS 4.8≥ 5.2.0.0, ≤ 5.2.6.5≥ 6.0.0.0, ≤ 6.0.3.2+2 more2020-11-16
CVE-2020-4705 [MEDIUM] CWE-79 CVE-2020-4705: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 is IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 187190.
nvd
CVE-2019-4377P4MEDIUMCVSS 4.3≥ 5.2.0.0, ≤ 6.0.0.1v6.0.0.0+1 more2019-06-25
CVE-2019-4377 [MEDIUM] CWE-209 CVE-2019-4377: IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 reveals sensitive information from a stack trace tha IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 reveals sensitive information from a stack trace that could be used in further attacks against the system. IBM X-Force ID: 162803.
nvd
CVE-2021-20372P4MEDIUMCVSS 4.3≥ 2.2.0.0, ≤ 5.2.6.5_3≥ 6.0.0.0, ≤ 6.0.0.6+2 more2021-10-07
CVE-2021-20372 [MEDIUM] CVE-2021-20372: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote authenticated user to cause a IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote authenticated user to cause a denial of another user's service due to insufficient permission checking. IBM X-Force ID: 195518.
nvd
CVE-2020-4299P4MEDIUMCVSS 4.3v5.2.0.0v6.0.3.12020-05-14
CVE-2020-4299 [MEDIUM] CVE-2020-4299: IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 could expose sensitive informat IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 could expose sensitive information to a user through a specially crafted HTTP request. IBM X-Force ID: 176606.
nvd
CVE-2017-1481P4MEDIUMCVSS 4.3v5.22017-12-07
CVE-2017-1481 [MEDIUM] CWE-200 CVE-2017-1481: IBM Sterling B2B Integrator Standard Edition 5.2 allows a user to view sensitive information that be IBM Sterling B2B Integrator Standard Edition 5.2 allows a user to view sensitive information that belongs to another user. IBM X-Force ID: 128619.
nvd
CVE-2020-4312P4MEDIUMCVSS 4.3≥ 5.2.0.0, ≤ 5.2.6.5≥ 6.0.0.0, ≤ 6.0.3.1+2 more2020-05-13
CVE-2020-4312 [MEDIUM] CVE-2020-4312: IBM Sterling B2B Integrator Standard Edition 5.2.0.0 trough 6.0.3.1 could allow an authenticated use IBM Sterling B2B Integrator Standard Edition 5.2.0.0 trough 6.0.3.1 could allow an authenticated user to obtain sensitive information from a cached web page. IBM X-Force ID: 177089.
nvd
CVE-2021-29761P4MEDIUMCVSS 4.3≥ 5.2.0.0, ≤ 6.1.0.3v6.0.0.0+7 more2021-10-06
CVE-2021-29761 [MEDIUM] CVE-2021-29761: IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated us IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensitive information from the dashboard that they should not have access to. IBM X-Force ID: 202265.
nvd
CVE-2024-45089P4MEDIUMCVSS 4.3≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2.0.0, ≤ 6.2.0.32025-01-31
CVE-2024-45089 [MEDIUM] CWE-203 CVE-2024-45089: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition EBI IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition EBICS server could allow an authenticated user to obtain sensitive filename information due to an observable discrepancy.
nvd
Ibm Sterling B2B Integrator vulnerabilities | cvebase