CVE-2024-47103: XSS
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Sterling B2B Integrator Standard Edition is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47103?
CVE-2024-47103 is classified as a high severity vulnerability due to its potential for privilege escalation and the ability to execute arbitrary code.
How do I fix CVE-2024-47103?
To fix CVE-2024-47103, upgrade IBM Sterling B2B Integrator to version 6.1.2.6 or later for versions 6.0.0.0 through 6.1.2.5, and to version 6.2.0.4 or later for versions 6.2.0.0 through 6.2.0.3.
Who is affected by CVE-2024-47103?
CVE-2024-47103 affects users of IBM Sterling B2B Integrator versions 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3.
What types of attacks can CVE-2024-47103 enable?
CVE-2024-47103 can enable cross-site scripting attacks, allowing attackers to execute malicious JavaScript code in the context of a privileged user's session.
What are the potential risks of CVE-2024-47103?
The potential risks of CVE-2024-47103 include unauthorized access, data manipulation, and loss of sensitive information due to the execution of harmful scripts.