First published: Wed Apr 10 2024(Updated: )
IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 268691.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling B2B Integrator | <=6.0.0.0 - 6.0.3.9 | |
IBM Sterling B2B Integrator | <=6.1.0.0 - 6.1.2.3 | |
IBM Sterling B2B Integrator | <=6.2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-45186 is a high-severity cross-site scripting vulnerability in IBM Sterling B2B Integrator.
CVE-2023-45186 allows a privileged user to embed arbitrary JavaScript code in the Web UI, potentially altering functionality.
IBM Sterling B2B Integrator versions 6.0.0.0 to 6.0.3.9, 6.1.0.0 to 6.1.2.3, and 6.2.0.0 are affected by CVE-2023-45186.
Mitigation for CVE-2023-45186 involves updating IBM Sterling B2B Integrator to the latest patched version that resolves the vulnerability.
Using unpatched versions of IBM Sterling B2B Integrator with CVE-2023-45186 poses security risks and it is recommended to update as soon as possible.