VendorsIBMsterling_b2b_integratorall versions
Vulnerabilities

IBM Sterling B2B Integrator

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

204CVEs
CVE-2023-50307
IBM Sterling B2B Integrator cross-site scripting
Published 2024-04-12 · Analyzed
5.4EPSS 0.003
CVE-2023-45186
IBM Sterling B2B Integrator cross-site scripting
Published 2024-04-12 · Analyzed
5.4EPSS 0.003
CVE-2021-20553
IBM Sterling B2B Integrator Standard Edition cross-site scripting
Published 2024-12-18 · Analyzed
5.4EPSS 0.003
CVE-2023-42014
IBM Sterling B2B Integrator Standard Edition cross-site scripting
Published 2024-06-27 · Modified
5.4EPSS 0.003
CVE-2025-33008
IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting
Published 2025-08-19 · Analyzed
5.4EPSS 0.002
CVE-2025-36298
Security Vulnerability in Ebics server affects IBM Sterling B2B Integrator and IBM Sterling File Gateway
Published 2026-07-30 · Analyzed
5.4EPSS 0.002
CVE-2025-36431
XSS Security Vulnerability in response header affects IBM Sterling B2B Integrator and IBM Sterling File Gateway
Published 2026-07-30 · Analyzed
5.4EPSS 0.002
CVE-2023-42011
IBM Sterling B2B Integrator Standard Edition tapjacking
Published 2024-06-27 · Modified
5.4EPSS 0.002
CVE-2023-32340
IBM Sterling B2B Integrator cross-site scripting
Published 2025-01-23 · Analyzed
5.4EPSS 0.002
CVE-2024-47116
IBM Sterling B2B Integrator cross-site scripting
Published 2025-01-31 · Analyzed
5.4EPSS 0.002
CVE-2024-40696
IBM Sterling B2B Integrator cross-site scripting
Published 2025-01-31 · Analyzed
5.4EPSS 0.002
CVE-2024-47103
IBM Sterling B2B Integrator cross-site scripting
Published 2025-01-31 · Analyzed
5.4EPSS 0.002
CVE-2025-14504
IBM Sterling B2B Integrator and IBM Sterling File Gateway Cross-Site Scripting
Published 2026-03-13 · Analyzed
5.4EPSS 0.002
CVE-2026-0835
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 are vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published 2026-03-13 · Analyzed
5.4EPSS 0.002
CVE-2023-40693
IBM Sterling B2B Integrator and IBM Sterling File Gateway Cross-Site Scripting
Published 2026-03-13 · Analyzed
5.4EPSS 0.002
CVE-2024-54183
IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting
Published 2025-06-18 · Analyzed
5.4EPSS 0.002
CVE-2025-2793
IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting
Published 2025-07-08 · Analyzed
5.4EPSS 0.002
CVE-2025-36135
IBM Sterling B2B Integrator and IBM Sterling File Gateway are Vulnerable to Cross-Site Scripting
Published 2025-11-07 · Analyzed
5.4EPSS 0.002
CVE-2018-1679
IBM Sterling B2B Integrator Standard Edition 5.2 through 5.2.6 could allow an unauthenticated user to obtain sensitive information that could be used in further attacks against the system. IBM X-Force ID: 145180.
Published 2018-07-20 · Modified
5.3EPSS 0.018
CVE-2014-0912
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to obtain sensitive product information via vectors related to an error page. IBM X-Force ID: 92072.
Published 2018-04-20 · Modified
5.3EPSS 0.017
CVE-2016-0210
IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to obtain sensitive information. By allowing HTTP OPTIONS method, a remote attacker could send a specially-crafted query to a vulnerable server running to cause the server to disclose sensitive information in the HTTP response.
Published 2017-02-08 · Modified
5.3EPSS 0.017
CVE-2020-4761
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 188895.
Published 2021-01-05 · Modified
5.3EPSS 0.013
CVE-2016-9983
IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user with special privileges to view files that they should not have access to. IBM X-Force ID: 120275.
Published 2017-06-22 · Modified
5.3EPSS 0.011
CVE-2016-5890
IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote authenticated users to change arbitrary passwords via unspecified vectors.
Published 2016-11-30 · Modified
5.3EPSS 0.011
CVE-2026-3482
IBM Sterling B2B Integrator and IBM Sterling File Gateway Authorization Bypass
Published 2026-07-22 · Analyzed
5.3EPSS 0.005
CVE-2024-27263
IBM Sterling B2B Integrator information disclosure
Published 2025-01-28 · Analyzed
5.3EPSS 0.003
CVE-2025-36112
IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure
Published 2025-11-24 · Analyzed
5.3EPSS 0.002
CVE-2018-1800
IBM Sterling B2B Integrator Standard Edition 5.2.6.0 and 6.2.6.1 could allow a local user to obtain highly sensitive information during a short time period when installation is occurring. IBM X-Force ID: 149607.
Published 2018-09-20 · Modified
5.1EPSS 0.003
CVE-2014-6199
The HTTP Server Adapter in IBM Sterling B2B Integrator 5.1 and 5.2.x and Sterling File Gateway 2.1 and 2.2 allows remote attackers to cause a denial of service (connection-slot exhaustion) via a crafted HTTP request.
Published 2015-01-10 · Modified
5.0EPSS 0.020
CVE-2013-0494
IBM Sterling B2B Integrator 5.0 and 5.1 allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted HTTP (1) Range or (2) Request-Range header.
Published 2013-08-09 · Modified
5.0EPSS 0.020
CVE-2012-5936
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Published 2013-07-03 · Modified
5.0EPSS 0.014
CVE-2013-0481
The console in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to read stack traces by triggering (1) an error or (2) an exception.
Published 2013-07-03 · Modified
5.0EPSS 0.014
CVE-2013-0539
An unspecified third-party component in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 uses short session ID values, which makes it easier for remote attackers to hijack sessions, and consequently obtain sensitive information, via a brute-force attack.
Published 2013-07-03 · Modified
5.0EPSS 0.014
CVE-2013-0558
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to obtain sensitive information about application implementation via unspecified vectors.
Published 2013-07-03 · Modified
5.0EPSS 0.014
CVE-2014-6099
The Change Password feature in IBM Sterling B2B Integrator 5.2.x through 5.2.4 does not have a lockout protection mechanism for invalid login requests, which makes it easier for remote attackers to obtain admin access via a brute-force approach.
Published 2014-10-26 · Modified
5.0EPSS 0.013
CVE-2013-5407
IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not properly restrict use of FRAME elements, which allows remote authenticated users to bypass intended access restrictions or obtain sensitive information via a crafted web site, related to a "frame injection" issue.
Published 2013-12-21 · Modified
4.9EPSS 0.008
CVE-2026-1918
IBM Sterling B2B Integrator and IBM Sterling File Gateway store sensitive information in a log file
Published 2026-07-28 · Analyzed
4.9EPSS 0.004
CVE-2025-36348
The Dashboard of IBM Sterling B2B Integrator and IBM Sterling File Gateway is Vulnerable to Information Disclosure
Published 2026-02-17 · Analyzed
4.9EPSS 0.003
CVE-2025-2667
IBM Sterling B2B Integrator information disclosure
Published 2025-09-04 · Analyzed
4.9EPSS 0.003
CVE-2020-4705
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 187190.
Published 2020-11-16 · Modified
4.8EPSS 0.006
← Prev4 / 6Next →