CVE-2023-50309: IBM Sterling B2B Integrator cross-site scripting
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Sterling B2B Integrator Standard Edition is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50309?
CVE-2023-50309 is classified as a moderate severity vulnerability due to the potential impact on user credentials.
How do I fix CVE-2023-50309?
To fix CVE-2023-50309, upgrade your IBM Sterling B2B Integrator to a version beyond 6.1.2.5.
What type of vulnerability is CVE-2023-50309?
CVE-2023-50309 is a stored cross-site scripting (XSS) vulnerability.
What versions are affected by CVE-2023-50309?
CVE-2023-50309 affects IBM Sterling B2B Integrator versions from 6.0.0.0 to 6.2.0.0, including versions 6.1.2.5.
What are the potential consequences of CVE-2023-50309?
The consequences of CVE-2023-50309 include the possibility of arbitrary JavaScript execution that could lead to credential disclosure.