CVE-2015-7437
- EPSS 0.04%
- Veröffentlicht 02.01.2016 21:59:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
Queue Watcher in IBM Sterling B2B Integrator 5.2 allows local users to obtain sensitive information via unspecified vectors.
CVE-2015-7431
- EPSS 0.23%
- Veröffentlicht 02.01.2016 21:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Queue Watcher in IBM Sterling B2B Integrator 5.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVE-2015-7410
- EPSS 0.23%
- Veröffentlicht 01.01.2016 05:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Health Check tool in IBM Sterling B2B Integrator 5.2 does not properly use cookies in conjunction with HTTPS sessions, which allows man-in-the-middle attackers to obtain sensitive information or modify data via unspecified vectors.
CVE-2015-5019
- EPSS 0.13%
- Veröffentlicht 08.11.2015 22:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
IBM Sterling Integrator 5.1 before 5010004_8 and Sterling B2B Integrator 5.2 before 5020500_9 allow remote authenticated users to read or upload files by leveraging a password-change requirement.
CVE-2015-4992
- EPSS 0.13%
- Veröffentlicht 06.10.2015 01:59:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
IBM Sterling B2B Integrator 5.2 before 5020500_8 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.
- EPSS 1.88%
- Veröffentlicht 10.01.2015 02:59:27
- Zuletzt bearbeitet 12.04.2025 10:46:40
The HTTP Server Adapter in IBM Sterling B2B Integrator 5.1 and 5.2.x and Sterling File Gateway 2.1 and 2.2 allows remote attackers to cause a denial of service (connection-slot exhaustion) via a crafted HTTP request.
CVE-2014-6146
- EPSS 0.06%
- Veröffentlicht 08.11.2014 11:55:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
IBM Sterling B2B Integrator 5.2.x through 5.2.4, when the Connect:Direct Server Adapter is configured, does not properly process the logging configuration, which allows local users to obtain sensitive information by reading log files.
- EPSS 0.28%
- Veröffentlicht 26.10.2014 18:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Change Password feature in IBM Sterling B2B Integrator 5.2.x through 5.2.4 does not have a lockout protection mechanism for invalid login requests, which makes it easier for remote attackers to obtain admin access via a brute-force approach.
CVE-2013-5413
- EPSS 0.27%
- Veröffentlicht 21.12.2013 14:22:57
- Zuletzt bearbeitet 11.04.2025 00:51:21
IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not invalidate a session upon a logout action, which allows remote attackers to bypass authentication by leveraging an unattended workstation.
CVE-2013-5405
- EPSS 0.18%
- Veröffentlicht 21.12.2013 14:22:56
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters.