CVE-2024-27263
- EPSS 0.03%
- Veröffentlicht 28.01.2025 01:15:08
- Zuletzt bearbeitet 04.03.2025 21:58:37
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to obtain sensitive information from the dashboard UI using man in the middle techniques.
CVE-2023-32340
- EPSS 0.03%
- Veröffentlicht 23.01.2025 03:15:08
- Zuletzt bearbeitet 04.03.2025 21:36:47
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cr...
CVE-2023-50309
- EPSS 0.03%
- Veröffentlicht 23.01.2025 03:15:08
- Zuletzt bearbeitet 04.03.2025 21:36:47
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadin...
CVE-2024-31903
- EPSS 14.19%
- Veröffentlicht 22.01.2025 16:15:29
- Zuletzt bearbeitet 05.03.2025 16:02:20
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 allow an attacker on the local network to execute arbitrary code on the system, caused by the deserialization of untrusted data.
CVE-2024-31913
- EPSS 0.06%
- Veröffentlicht 06.01.2025 16:15:28
- Zuletzt bearbeitet 05.03.2025 16:02:20
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended...
CVE-2024-31914
- EPSS 0.18%
- Veröffentlicht 06.01.2025 16:15:28
- Zuletzt bearbeitet 29.09.2025 22:17:43
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended...
CVE-2021-20553
- EPSS 0.05%
- Veröffentlicht 19.12.2024 00:15:04
- Zuletzt bearbeitet 06.03.2025 19:02:47
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading ...
CVE-2023-42010
- EPSS 0.12%
- Veröffentlicht 17.07.2024 18:15:03
- Zuletzt bearbeitet 21.11.2024 08:22:05
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 could disclose sensitive information in the HTTP response using man in the middle techniques. IBM X-Force ID: 265507.
CVE-2023-42011
- EPSS 0.05%
- Veröffentlicht 27.06.2024 18:15:13
- Zuletzt bearbeitet 21.11.2024 08:22:06
IBM Sterling B2B Integrator Standard Edition 6.1 and 6.2 does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interactin...
CVE-2023-42014
- EPSS 0.07%
- Veröffentlicht 27.06.2024 18:15:13
- Zuletzt bearbeitet 21.11.2024 08:22:06
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.2.0.2 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality pote...