CVE-2020-4564: XSS
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 and IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 183933.
Other sources
IBM Sterling B2B Integrator Standard Edition and IBM Sterling File Gateway are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2020-4564.
Which IBM products are affected by this vulnerability?
IBM Sterling B2B Integrator Standard Edition and IBM Sterling File Gateway are affected.
What is the severity of CVE-2020-4564?
The severity of CVE-2020-4564 is medium (5.4).
How does this vulnerability occur?
This vulnerability allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to cross-site scripting.
How can I fix CVE-2020-4564?
You can fix CVE-2020-4564 by applying the patch provided by IBM or upgrading to a fixed version of the affected products.