CVE-2017-1348: XSS
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126524.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1348?
CVE-2017-1348 is rated as a medium severity vulnerability due to its potential for credential disclosure.
How do I fix CVE-2017-1348?
To fix CVE-2017-1348, upgrade to a patched version of IBM Sterling B2B Integrator, specifically version 5.2 or later.
What type of vulnerability is CVE-2017-1348?
CVE-2017-1348 is a cross-site scripting (XSS) vulnerability affecting the web user interface.
What are the potential impacts of CVE-2017-1348?
The impacts of CVE-2017-1348 include the possibility of arbitrary JavaScript execution, which could lead to user credential disclosure in a trusted session.
Who is affected by CVE-2017-1348?
CVE-2017-1348 affects users of IBM Sterling B2B Integrator Standard Edition version 5.2.