First published: Thu Feb 28 2019(Updated: )
IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 155907.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM B2B Sterling Integrator | >=5.2.0.1<=6.0.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4029 has been rated as a high severity vulnerability due to its potential for credential disclosure.
To fix CVE-2019-4029, it is recommended to update IBM Sterling B2B Integrator to the latest version that addresses this vulnerability.
CVE-2019-4029 can facilitate cross-site scripting attacks that allow attackers to execute arbitrary JavaScript code in a user's browser.
IBM Sterling B2B Integrator versions 5.2.0.1 through 6.0.0.0 are affected by CVE-2019-4029.
Failing to address CVE-2019-4029 may lead to unauthorized access to user credentials within a trusted session.