VendorsIBMsterling_b2b_integratorall versions
Vulnerabilities

IBM Sterling B2B Integrator

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

204CVEs
CVE-2017-1131
IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information by using unsupported, specially crafted HTTP commands. IBM X-Force ID: 121375.
Published 2017-06-23 · Modified
6.5EPSS 0.014
CVE-2015-0194
XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling File Gateway 2.1 and 2.2 allows remote attackers to read arbitrary files via a crafted XML data.
Published 2017-08-02 · Modified
6.5EPSS 0.014
CVE-2016-9982
IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information such as account lists due to improper access control. IBM X-Force ID: 120274.
Published 2017-06-22 · Modified
6.5EPSS 0.012
CVE-2017-1193
IBM Sterling B2B Integrator Standard Edition 5.2 could allow user to obtain sensitive information using an HTTP GET request. IBM X-Force ID: 123667.
Published 2017-06-23 · Modified
6.5EPSS 0.012
CVE-2020-4475
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Published 2020-11-16 · Modified
6.5EPSS 0.011
CVE-2013-2982
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to upload arbitrary files via unspecified vectors.
Published 2013-07-03 · Modified
6.5EPSS 0.011
CVE-2021-39033
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 213963.
Published 2022-04-19 · Modified
6.5EPSS 0.010
CVE-2020-4671
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 stores potentially sensitive information in log files that could be read by an authenticatedl user. IBM X-Force ID: 186284.
Published 2020-11-16 · Modified
6.5EPSS 0.010
CVE-2020-4566
IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2 stores potentially highly sensitive information in log files that could be read by an authenticated user. IBM X-Force ID: 184083.
Published 2020-11-16 · Modified
6.5EPSS 0.010
CVE-2012-5766
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to execute arbitrary SQL commands via vectors involving the RNVisibility page and unspecified screens, a different vulnerability than CVE-2013-0560.
Published 2013-07-03 · Modified
6.5EPSS 0.010
CVE-2013-5409
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Published 2013-12-21 · Modified
6.5EPSS 0.010
CVE-2022-22482
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow an authenticated user to upload files that could fill up the filesystem and cause a denial of service. IBM X-Force ID: 225977.
Published 2022-05-17 · Modified
6.5EPSS 0.010
CVE-2013-0560
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2012-5766.
Published 2013-07-03 · Modified
6.5EPSS 0.010
CVE-2020-4692
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 could allow an authenticated user to obtain sensitive information from the Dashboard UI. IBM X-Force ID: 186780.
Published 2020-11-16 · Modified
6.5EPSS 0.009
CVE-2019-4597
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 167880.
Published 2020-02-26 · Modified
6.5EPSS 0.008
CVE-2019-4598
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 167881.
Published 2020-02-26 · Modified
6.5EPSS 0.008
CVE-2021-20375
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to intercept and replace a message sent by another user due to improper access controls. IBM X-Force ID: 195567.
Published 2021-10-07 · Modified
6.5EPSS 0.008
CVE-2021-39087
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow an authenticated user to obtain sensitive information due to improper permission controls. IBM X-Force ID: 216109.
Published 2022-08-16 · Modified
6.5EPSS 0.006
CVE-2023-32341
IBM Sterling B2B Integrator denial of service
Published 2024-02-09 · Modified
6.5EPSS 0.006
CVE-2019-4738
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.1 discloses sensitive information to an authenticated user from the dashboard UI which could be used in further attacks against the system. IBM X-Force ID: 172753.
Published 2020-12-10 · Modified
6.5EPSS 0.005
CVE-2023-22876
IBM Sterling B2B Integrator information disclosure
Published 2023-03-15 · Modified
6.5EPSS 0.005
CVE-2022-22337
IBM Sterling B2B Integrator Standard Edition information disclosure
Published 2023-01-04 · Modified
6.5EPSS 0.005
CVE-2022-22371
IBM Sterling B2B Integrator Standard Edition session fixation
Published 2023-01-04 · Modified
6.5EPSS 0.003
CVE-2026-7362
Improper Access Control Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway
Published 2026-07-28 · Analyzed
6.5EPSS 0.003
CVE-2025-2988
IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure
Published 2025-08-19 · Analyzed
6.5EPSS 0.003
CVE-2025-14483
IBM Sterling B2B Integrator and IBM Sterling File Gateway Information Disclosure
Published 2026-03-13 · Analyzed
6.5EPSS 0.002
CVE-2013-0476
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to inject arbitrary FTP commands via unspecified vectors.
Published 2013-07-03 · Modified
6.4EPSS 0.011
CVE-2021-29764
IBM Sterling B2B Integrator 5.2.0.0 through 6.1.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 202268.
Published 2021-10-06 · Modified
6.4EPSS 0.005
CVE-2024-31914
IBM Sterling B2B Integrator cross-site scripting
Published 2025-01-06 · Analyzed
6.4EPSS 0.002
CVE-2023-50309
IBM Sterling B2B Integrator cross-site scripting
Published 2025-01-23 · Analyzed
6.4EPSS 0.002
CVE-2024-49807
IBM Sterling B2B Integrator cross-site scripting
Published 2025-01-31 · Analyzed
6.4EPSS 0.002
CVE-2025-3630
IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting
Published 2025-07-08 · Analyzed
6.4EPSS 0.002
CVE-2023-25682
IBM Sterling B2B Integrator information disclosure
Published 2023-11-22 · Modified
6.2EPSS 0.002
CVE-2016-3057
Cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2016-11-30 · Modified
6.1EPSS 0.011
CVE-2015-7431
Cross-site scripting (XSS) vulnerability in Queue Watcher in IBM Sterling B2B Integrator 5.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Published 2016-01-02 · Modified
6.1EPSS 0.008
CVE-2016-6020
IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
Published 2017-02-01 · Modified
6.1EPSS 0.008
CVE-2020-4657
IBM Sterling B2B Integrator 5.2.0.0 through 6.0.3.2 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186094.
Published 2020-12-16 · Modified
6.1EPSS 0.007
CVE-2021-20561
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199230.
Published 2021-10-07 · Modified
6.1EPSS 0.006
CVE-2022-34330
IBM Sterling B2B Integrator cross-site scripting
Published 2023-01-04 · Modified
6.1EPSS 0.004
CVE-2025-33014
IBM Sterling B2B Integrator and IBM Sterling File Gateway link injection
Published 2025-07-18 · Analyzed
6.1EPSS 0.002
← Prev2 / 6Next →