First published: Fri Jul 20 2018(Updated: )
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142967.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling B2B Integrator | >=5.2.0.1<=5.2.6.3 | |
IBM Sterling File Gateway | >=2.2.0<=2.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2018-1563.
The severity of CVE-2018-1563 is medium with a severity value of 5.4.
The affected software for CVE-2018-1563 is IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6).
The CWE ID for this vulnerability is CWE-79.
This vulnerability can be exploited by users embedding arbitrary JavaScript code in the Web UI, potentially leading to credential disclosure.