Skip to main content

Vendor/product archive

ibm / sterling_b2b_integrator CVEs

Beta · best-effort

201 CVEs tagged to ibm / sterling_b2b_integrator5 Critical, 22 High, 162 Medium, 12 Low, 0 Unrated.

CVE-2017-1193

Published Jun 23, 2017

IBM Sterling B2B Integrator Standard Edition 5.2 could allow user to obtain sensitive information using an HTTP GET request. IBM X-Force ID: 123667.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1132

Published Jun 23, 2017

IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alter…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1131

Published Jun 23, 2017

IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information by using unsupported, specially crafted HTTP commands. IBM X-For…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5893

Published Jun 23, 2017

IBM Sterling B2B Integrator Standard Edition 5.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 115336.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1326

Published Jun 22, 2017

IBM Sterling File Gateway does not properly restrict user requests based on permission level. This allows for users to update data related to other users, by manipulating the para…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9983

Published Jun 22, 2017

IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user with special privileges to view files that they should not have access to. IBM X-Force ID: 12027…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9982

Published Jun 22, 2017

IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information such as account lists due to improper access control. IBM X-Forc…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0210

Published Feb 8, 2017

IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to obtain sensitive information. By allowing HTTP OPTIONS method, a remote attacker could send a special…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6020

Published Feb 1, 2017

IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5890

Published Nov 30, 2016

IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote authenticated users to change arbitrary passwords via unspecified vectors.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3057

Published Nov 30, 2016

Cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote attackers to inject arbitrary web script or…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7450

Published Jan 2, 2016

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
36.9
KEV listed

CVE-2015-7438

Published Jan 2, 2016

IBM Sterling B2B Integrator 5.2 allows local users to obtain sensitive cleartext web-services information by leveraging database access.

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7437

Published Jan 2, 2016

Queue Watcher in IBM Sterling B2B Integrator 5.2 allows local users to obtain sensitive information via unspecified vectors.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7431

Published Jan 2, 2016

Cross-site scripting (XSS) vulnerability in Queue Watcher in IBM Sterling B2B Integrator 5.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7410

Published Jan 1, 2016

The Health Check tool in IBM Sterling B2B Integrator 5.2 does not properly use cookies in conjunction with HTTPS sessions, which allows man-in-the-middle attackers to obtain sensi…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4992

Published Oct 6, 2015

IBM Sterling B2B Integrator 5.2 before 5020500_8 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-6146

Published Nov 8, 2014

IBM Sterling B2B Integrator 5.2.x through 5.2.4, when the Connect:Direct Server Adapter is configured, does not properly process the logging configuration, which allows local user…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-6099

Published Oct 26, 2014

The Change Password feature in IBM Sterling B2B Integrator 5.2.x through 5.2.4 does not have a lockout protection mechanism for invalid login requests, which makes it easier for r…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 151-175 of 201 CVEsPage 7 of 9