First published: Tue Feb 21 2023(Updated: )
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 238683.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling B2B Integrator | <=6.0.0.0 - 6.0.3.7 | |
IBM Sterling B2B Integrator | <=6.1.0.0 - 6.1.2.0 | |
IBM Sterling B2B Integrator | >=6.0.0.0<=6.0.3.7 | |
IBM Sterling B2B Integrator | >=6.1.0.0<=6.1.2.0 | |
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43578 is a vulnerability found in IBM Sterling B2B Integrator Standard Edition that allows users to embed arbitrary JavaScript code in the web UI, potentially leading to credentials disclosure.
CVE-2022-43578 affects IBM Sterling B2B Integrator Standard Edition versions 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0.
CVE-2022-43578 has a severity rating of 5.4, which is considered medium.
To fix CVE-2022-43578, update IBM Sterling B2B Integrator Standard Edition to a version higher than 6.1.2.0.
You can find more information about CVE-2022-43578 on the IBM X-Force Exchange website and the IBM Support page.