CVE-2019-4075: XSS
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 157109.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4075?
CVE-2019-4075 is classified as a medium severity vulnerability due to its potential to enable cross-site scripting attacks.
How do I fix CVE-2019-4075?
To mitigate CVE-2019-4075, upgrade to IBM Sterling B2B Integrator versions 6.0.0.2 or later where the issue is resolved.
What systems are affected by CVE-2019-4075?
CVE-2019-4075 affects IBM Sterling B2B Integrator versions 6.0.0.0 and 6.0.0.1.
What are the risks associated with CVE-2019-4075?
The risks associated with CVE-2019-4075 include the potential for credential disclosure and the unauthorized execution of JavaScript in a trusted session.
Is user action required to exploit CVE-2019-4075?
Yes, user action is required to exploit CVE-2019-4075, as it involves embedding JavaScript into the web UI.