First published: Fri Jun 23 2017(Updated: )
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126524.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM B2B Sterling Integrator | =5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1348 is rated as a medium severity vulnerability due to its potential for credential disclosure.
To fix CVE-2017-1348, upgrade to a patched version of IBM Sterling B2B Integrator, specifically version 5.2 or later.
CVE-2017-1348 is a cross-site scripting (XSS) vulnerability affecting the web user interface.
The impacts of CVE-2017-1348 include the possibility of arbitrary JavaScript execution, which could lead to user credential disclosure in a trusted session.
CVE-2017-1348 affects users of IBM Sterling B2B Integrator Standard Edition version 5.2.