First published: Wed Jul 03 2013(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-2983.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM B2B Sterling Integrator | =5.1 | |
IBM B2B Sterling Integrator | =5.2 | |
IBM Sterling File Gateway | =2.1 | |
IBM Sterling File Gateway | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0468 has a medium severity rating due to its potential for enabling XSS attacks.
To mitigate CVE-2013-0468, upgrade IBM Sterling B2B Integrator to version 5.3 or later and IBM Sterling File Gateway to version 2.3 or later.
CVE-2013-0468 affects users of IBM Sterling B2B Integrator versions 5.1 and 5.2, as well as IBM Sterling File Gateway versions 2.1 and 2.2.
CVE-2013-0468 allows authenticated remote users to perform Cross-Site Scripting (XSS) attacks.
Yes, CVE-2013-0468 is a known XSS vulnerability within certain IBM Sterling B2B Integrator and File Gateway versions.