CVE-2023-40693: IBM Sterling B2B Integrator and IBM Sterling File Gateway Cross-Site Scripting
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.72, and 6.2.0.0 through 6.2.0.51, 6.2.1.0 through 6.2.1.11 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-40693?
CVE-2023-40693 is considered a high-severity vulnerability due to its potential for exploitation via cross-site scripting.
How do I fix CVE-2023-40693?
To remediate CVE-2023-40693, users should upgrade to IBM Sterling B2B Integrator or IBM Sterling File Gateway versions that are not affected, specifically beyond version 6.1.2.7_2 for 6.1.0.x and beyond 6.2.0.5_1 for 6.2.0.x.
What impact does CVE-2023-40693 have on my system?
CVE-2023-40693 allows attackers to execute arbitrary scripts in the context of the user's session, which can lead to data theft or manipulation.
Which versions of IBM Sterling are affected by CVE-2023-40693?
IBM Sterling B2B Integrator and IBM Sterling File Gateway versions ranging from 6.1.0.0 to 6.1.2.7_2 and 6.2.0.0 to 6.2.1.1_1 are affected by CVE-2023-40693.
Is there a workaround for CVE-2023-40693?
There are no specific workarounds for CVE-2023-40693, and the recommended action is to apply the necessary software updates to eliminate the vulnerability.