First published: Wed Oct 06 2021(Updated: )
IBM Sterling B2B Integrator Standard Edition 5.2.0.0. through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204912.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling B2B Integrator | >=5.2.0.0<=6.0.3.4 | |
IBM Sterling B2B Integrator | >=6.1.0.0<=6.1.0.3 | |
<=5.2.0.0 - 6.0.3.4 | ||
<=6.1.0.0 - 6.1.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2021-29836.
The severity of CVE-2021-29836 is medium with a CVSS score of 5.4.
CVE-2021-29836 allows users to embed arbitrary JavaScript code in the Web UI of IBM Sterling B2B Integrator, potentially leading to credentials disclosure within a trusted session.
IBM Sterling B2B Integrator versions 5.2.0.0 to 6.0.3.4 and versions 6.1.0.0 to 6.1.0.3 are affected by CVE-2021-29836.
You can fix CVE-2021-29836 in IBM Sterling B2B Integrator by applying the patch provided by IBM. Please refer to the following URL for patch download: [Patch Download](http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~Other%2Bsoftware&product=ibm/Other+software/Sterling+B2B+Integrator&release=All&platform=All&function=all)