VendorsIBMsterling_b2b_integratorall versions
Vulnerabilities

IBM Sterling B2B Integrator

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

204CVEs
CVE-2015-7450
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
Published 2016-01-02 · Analyzed
10.0KEV1 PoCEPSS 0.978
CVE-2021-29903
IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 207506.
Published 2021-10-06 · Modified
9.8EPSS 0.011
CVE-2021-29798
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 203734.
Published 2021-10-06 · Modified
9.8EPSS 0.011
CVE-2021-39085
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 215888.
Published 2022-08-16 · Modified
9.8EPSS 0.009
CVE-2022-22338
IBM Sterling B2B Integrator Standard Edition SQL injection
Published 2023-01-04 · Modified
9.8EPSS 0.007
CVE-2023-50316
IBM Sterling B2B Integrator information disclosure
Published 2025-01-28 · Analyzed
9.8EPSS 0.004
CVE-2012-5937
Unspecified vulnerability in the CLA2 server in IBM Gentran Integration Suite 4.3, Sterling Integrator 5.0 and 5.1, and Sterling B2B Integrator 5.2, as used in IBM Sterling File Gateway 1.1 through 2.2 and other products, allows remote attackers to execute arbitrary commands via unknown vectors.
Published 2013-04-12 · Modified
9.3EPSS 0.026
CVE-2019-4728
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code with SYSTEM privileges. IBM X-Force ID: 172452.
Published 2021-01-05 · Modified
9.0EPSS 0.050
CVE-2017-1174
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 123296.
Published 2017-08-10 · Modified
8.8EPSS 0.015
CVE-2017-1347
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 126462.
Published 2017-06-23 · Modified
8.8EPSS 0.015
CVE-2020-4655
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 186091.
Published 2020-11-16 · Modified
8.8EPSS 0.013
CVE-2020-4762
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow an authenticated user to create a privileged account due to improper access controls. IBM X-Force ID: 188896.
Published 2021-01-05 · Modified
8.8EPSS 0.013
CVE-2020-4700
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 could allow an authenticated user belonging to a specific user group to create a user or group with administrative privileges. IBM X-Force ID: 187077.
Published 2020-11-16 · Modified
8.8EPSS 0.012
CVE-2019-4387
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.2.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 162715.
Published 2019-11-26 · Modified
8.8EPSS 0.010
CVE-2019-4680
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.2.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 171733.
Published 2020-10-20 · Modified
8.8EPSS 0.010
CVE-2024-31903
IBM Sterling B2B Integrator Standard Edition code execution
Published 2025-01-22 · Analyzed
8.8EPSS 0.010
CVE-2022-40231
IBM Sterling B2B Integrator Standard Edition improper access control
Published 2023-02-17 · Modified
8.8EPSS 0.006
CVE-2022-43920
IBM Sterling B2B Integrator Standard Edition privilege escalation
Published 2023-01-04 · Modified
8.8EPSS 0.005
CVE-2022-40232
IBM Sterling B2B Integrator Standard Edition improper access control
Published 2023-02-17 · Modified
8.8EPSS 0.005
CVE-2021-29837
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 204913.
Published 2021-10-06 · Modified
8.8EPSS 0.004
CVE-2020-4668
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 186283.
Published 2022-04-08 · Modified
8.8EPSS 0.004
CVE-2022-35638
IBM Sterling B2B Integrator cross-site request forgery
Published 2023-11-22 · Modified
8.8EPSS 0.003
CVE-2023-38739
IBM Sterling B2B Integrator cross-site request forgery
Published 2025-01-31 · Analyzed
8.8EPSS 0.002
CVE-2017-1192
IBM Sterling B2B Integrator 5.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 123663.
Published 2017-08-10 · Modified
8.2EPSS 0.023
CVE-2014-0927
The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to bypass authentication by leveraging knowledge of the port number and webapp path. IBM X-Force ID: 92259.
Published 2018-04-20 · Modified
8.1EPSS 0.023
CVE-2026-7769
SQL injection Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway
Published 2026-07-28 · Analyzed
8.1EPSS 0.005
CVE-2021-20584
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote attacker to upload arbitrary files, caused by improper access controls. IBM X-Force ID: 199397.
Published 2021-10-07 · Modified
7.5EPSS 0.014
CVE-2018-1720
IBM Sterling B2B Integrator Standard Edition 5.2.0.1, 5.2.6.3_6, 6.0.0.0, and 6.0.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 147294.
Published 2019-04-25 · Modified
7.5EPSS 0.010
CVE-2020-4937
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 191814.
Published 2020-11-20 · Modified
7.5EPSS 0.008
CVE-2021-38925
IBM Sterling B2B Integrator Standard Edition 5.2.0. 0 through 6.1.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210171.
Published 2021-10-06 · Modified
7.5EPSS 0.007
CVE-2025-14031
IBM Sterling B2B Integrator and IBM Sterling File Gateway Denial of Service
Published 2026-03-17 · Analyzed
7.5EPSS 0.003
CVE-2025-36134
IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure
Published 2025-11-25 · Analyzed
7.5EPSS 0.003
CVE-2015-7410
The Health Check tool in IBM Sterling B2B Integrator 5.2 does not properly use cookies in conjunction with HTTPS sessions, which allows man-in-the-middle attackers to obtain sensitive information or modify data via unspecified vectors.
Published 2016-01-01 · Modified
7.4EPSS 0.009
CVE-2025-36368
IBM Sterling B2B Integrator and IBM Sterling File Gateway SQL Injection
Published 2026-03-13 · Analyzed
7.2EPSS 0.003
CVE-2013-4002
XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, Java SE Embedded 7u40 and earlier, and possibly other products allows remote attackers to cause a denial of service via vectors related to XML attribute names.
Published 2013-07-23 · Modified
7.1EPSS 0.247
CVE-2019-4043
IBM Sterling B2B Integrator Standard Edition 5.2.0 snf 6.0.0.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 156239.
Published 2019-04-02 · Modified
7.1EPSS 0.024
CVE-2026-1264
IBM Sterling B2B Integrator and IBM Sterling File Gateway Improper Access Controls
Published 2026-03-17 · Analyzed
7.1EPSS 0.002
CVE-2019-4595
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 167878.
Published 2020-02-24 · Modified
6.8EPSS 0.007
CVE-2018-1564
IBM Sterling B2B Integrator Standard Edition 5.2 through 5.2.6 could allow a local user with administrator privileges to obtain user passwords found in debugging messages. IBM X-Force ID: 142968.
Published 2018-07-20 · Modified
6.7EPSS 0.004
CVE-2013-2984
Directory traversal vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote authenticated users to read or modify files via unspecified vectors.
Published 2013-07-03 · Modified
6.5EPSS 0.015
1 / 6Next →