First published: Mon Mar 10 2025(Updated: )
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling B2B Integrator | >=6.0.0.0<=6.1.2.6>=6.2.0.0<=6.2.0.3 | |
IBM B2B Sterling Integrator | <=6.0.0.0 - 6.1.2.6 | |
IBM B2B Sterling Integrator | <=6.2.0.0 - 6.2.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-56338 has been identified as a high-severity vulnerability due to its potential exploitation by privileged users.
To fix CVE-2024-56338, it is recommended to upgrade IBM Sterling B2B Integrator to versions 6.1.2.7 or 6.2.0.4 or later.
CVE-2024-56338 affects users of IBM Sterling B2B Integrator Standard Edition versions 6.0.0.0 to 6.1.2.6 and 6.2.0.0 to 6.2.0.3.
CVE-2024-56338 is a cross-site scripting (XSS) vulnerability that allows the injection of arbitrary JavaScript code.
Yes, CVE-2024-56338 can be exploited remotely by a privileged user who has access to the Web UI.