First published: Tue Oct 05 2021(Updated: )
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 205684.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling B2B Integrator | >=5.2.0.0<=6.0.3.4 | |
IBM Sterling B2B Integrator | >=6.1.0.0<=6.1.0.3 | |
<=5.2.0.0 - 6.0.3.4 | ||
<=6.1.0.0 - 6.1.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-29855.
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is affected by this vulnerability.
The severity of CVE-2021-29855 is medium (5.4).
To fix this vulnerability, apply the patch provided by IBM for the affected versions of IBM Sterling B2B Integrator Standard Edition.
You can find more information about CVE-2021-29855 on the IBM X-Force Exchange website and the IBM Support page.