Show filters
170 Total Results
Displaying 61-70 of 170
Sort by:
Attacker Value
Unknown
CVE-2021-20562
Disclosure Date: July 26, 2021 (last updated February 23, 2025)
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_3 and 6.1.0.0 through 6.1.0.2 vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199232.
0
Attacker Value
Unknown
CVE-2020-4646
Disclosure Date: May 18, 2021 (last updated February 22, 2025)
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5, 6.0.0.0 through 6.0.3.3, and 6.1.0.0 through 6.1.0.2 could allow an authenticated user to view pages they shoiuld not have access to due to improper authorization control.
0
Attacker Value
Unknown
CVE-2020-4761
Disclosure Date: January 04, 2021 (last updated February 22, 2025)
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 188895.
0
Attacker Value
Unknown
CVE-2019-4728
Disclosure Date: January 04, 2021 (last updated February 22, 2025)
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code with SYSTEM privileges. IBM X-Force ID: 172452.
0
Attacker Value
Unknown
CVE-2020-4762
Disclosure Date: January 04, 2021 (last updated February 22, 2025)
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow an authenticated user to create a privileged account due to improper access controls. IBM X-Force ID: 188896.
0
Attacker Value
Unknown
CVE-2020-4657
Disclosure Date: December 15, 2020 (last updated February 22, 2025)
IBM Sterling B2B Integrator 5.2.0.0 through 6.0.3.2 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186094.
0
Attacker Value
Unknown
CVE-2019-4738
Disclosure Date: December 09, 2020 (last updated February 22, 2025)
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.1 discloses sensitive information to an authenticated user from the dashboard UI which could be used in further attacks against the system. IBM X-Force ID: 172753.
0
Attacker Value
Unknown
CVE-2020-4937
Disclosure Date: November 19, 2020 (last updated February 22, 2025)
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 191814.
0
Attacker Value
Unknown
CVE-2020-4700
Disclosure Date: November 13, 2020 (last updated November 28, 2024)
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 could allow an authenticated user belonging to a specific user group to create a user or group with administrative privileges. IBM X-Force ID: 187077.
0
Attacker Value
Unknown
CVE-2020-4692
Disclosure Date: November 13, 2020 (last updated November 28, 2024)
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 could allow an authenticated user to obtain sensitive information from the Dashboard UI. IBM X-Force ID: 186780.
0