First published: Tue Oct 13 2020(Updated: )
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 and IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 183933.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling B2B Integrator | >=5.2.0.0<=6.0.3.1 | |
IBM Sterling File Gateway | >=2.2.0.0<=6.0.3.1 | |
<=2.2.0.0 - 6.0.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-4564.
IBM Sterling B2B Integrator Standard Edition and IBM Sterling File Gateway are affected.
The severity of CVE-2020-4564 is medium (5.4).
This vulnerability allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to cross-site scripting.
You can fix CVE-2020-4564 by applying the patch provided by IBM or upgrading to a fixed version of the affected products.