First published: Fri Feb 10 2023(Updated: )
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 238684.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling B2B Integrator | <=6.0.0.0 - 6.0.3.7 | |
IBM Sterling B2B Integrator | <=6.1.0.0 - 6.1.2.0 | |
IBM Sterling B2B Integrator | >=6.0.0.0<=6.0.3.7 | |
IBM Sterling B2B Integrator | >=6.1.0.0<=6.1.2.0 | |
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-43579.
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 are affected by this vulnerability.
The severity rating of CVE-2022-43579 is medium with a score of 5.4 (out of 10).
This vulnerability allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure and alteration of intended functionality.
IBM has provided fixes for this vulnerability. Please refer to the official IBM support page for more information.