First published: Thu Dec 07 2017(Updated: )
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128620.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM B2B Sterling Integrator | =5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1482 is classified as a medium severity vulnerability due to its potential to allow arbitrary JavaScript code execution.
To fix CVE-2017-1482, update to the latest version of IBM Sterling B2B Integrator that addresses this vulnerability.
CVE-2017-1482 facilitates cross-site scripting (XSS) attacks, allowing attackers to execute malicious scripts in a trusted user's session.
Yes, CVE-2017-1482 specifically affects IBM Sterling B2B Integrator version 5.2.
The impact of CVE-2017-1482 can include unauthorized access to sensitive information, such as user credentials, as a result of executing malicious scripts.