VendorsIBMsterling_b2b_integratorall versions
Vulnerabilities

IBM Sterling B2B Integrator

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

204CVEs
CVE-2024-56338
IBM Sterling B2B Integrator cross-site scripting
Published 2025-03-11 · Analyzed
4.8EPSS 0.003
CVE-2025-2694
IBM Sterling B2B Integrator cross-site scripting
Published 2025-09-04 · Analyzed
4.8EPSS 0.002
CVE-2015-7438
IBM Sterling B2B Integrator 5.2 allows local users to obtain sensitive cleartext web-services information by leveraging database access.
Published 2016-01-02 · Modified
4.7EPSS 0.003
CVE-2017-1633
IBM Sterling B2B Integrator 5.2 through 5.2.6 could allow an authenticated attacker to obtain sensitive variable name information using specially crafted HTTP requests. IBM X-Force ID: 133180.
Published 2018-07-20 · Modified
4.3EPSS 0.017
CVE-2019-4377
IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 reveals sensitive information from a stack trace that could be used in further attacks against the system. IBM X-Force ID: 162803.
Published 2019-06-25 · Modified
4.3EPSS 0.013
CVE-2013-5413
IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not invalidate a session upon a logout action, which allows remote attackers to bypass authentication by leveraging an unattended workstation.
Published 2013-12-21 · Modified
4.3EPSS 0.013
CVE-2021-20372
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote authenticated user to cause a denial of another user's service due to insufficient permission checking. IBM X-Force ID: 195518.
Published 2021-10-07 · Modified
4.3EPSS 0.012
CVE-2013-5411
IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote attackers to inject links and trigger unintended navigation or actions via unspecified vectors.
Published 2013-12-21 · Modified
4.3EPSS 0.012
CVE-2019-4222
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 could allow an authenticated user to view process definition of a business process without permission. IBM X-Force ID: 159231.
Published 2019-04-25 · Modified
4.3EPSS 0.012
CVE-2013-0455
Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling B2B Integrator 5.2.4 and Sterling File Gateway allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2013-07-02 · Modified
4.3EPSS 0.009
CVE-2017-1481
IBM Sterling B2B Integrator Standard Edition 5.2 allows a user to view sensitive information that belongs to another user. IBM X-Force ID: 128619.
Published 2017-12-07 · Modified
4.3EPSS 0.009
CVE-2021-29700
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authneticated attacker to obtain sensitive information from configuration files that could aid in further attacks against the system. IBM X-Force ID: 200656.
Published 2021-10-07 · Modified
4.3EPSS 0.009
CVE-2020-4312
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 trough 6.0.3.1 could allow an authenticated user to obtain sensitive information from a cached web page. IBM X-Force ID: 177089.
Published 2020-05-13 · Modified
4.3EPSS 0.008
CVE-2017-1326
IBM Sterling File Gateway does not properly restrict user requests based on permission level. This allows for users to update data related to other users, by manipulating the parameters passed in the POST request. IBM X-Force ID: 126060.
Published 2017-06-22 · Modified
4.3EPSS 0.008
CVE-2021-20376
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated attacker to enumerate usernames due to there being an observable discrepancy in returned messages. IBM X-Force ID: 195568.
Published 2021-10-07 · Modified
4.3EPSS 0.007
CVE-2021-29761
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensitive information from the dashboard that they should not have access to. IBM X-Force ID: 202265.
Published 2021-10-06 · Modified
4.3EPSS 0.007
CVE-2020-4646
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5, 6.0.0.0 through 6.0.3.3, and 6.1.0.0 through 6.1.0.2 could allow an authenticated user to view pages they shoiuld not have access to due to improper authorization control.
Published 2021-05-19 · Modified
4.3EPSS 0.007
CVE-2021-38954
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could disclose sensitive version information that could aid in future attacks against the system. IBM X-Force ID: 211414.
Published 2022-06-30 · Modified
4.3EPSS 0.007
CVE-2021-29758
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to perform actions that they should not be able to access due to improper access controls. IBM X-Force ID: 202169.
Published 2021-10-06 · Modified
4.3EPSS 0.006
CVE-2019-4726
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 172363.
Published 2020-02-26 · Modified
4.3EPSS 0.005
CVE-2026-3157
Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway due to information disclosure in mailbox UI
Published 2026-07-28 · Analyzed
4.3EPSS 0.003
CVE-2026-3158
Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway due to information disclosure
Published 2026-07-28 · Analyzed
4.3EPSS 0.003
CVE-2024-45089
IBM Sterling B2B Integrator information disclosure
Published 2025-01-31 · Analyzed
4.3EPSS 0.003
CVE-2023-42016
IBM Sterling B2B Integrator information disclosure
Published 2024-02-09 · Modified
4.3EPSS 0.003
CVE-2024-54172
IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site request forgery
Published 2025-06-18 · Analyzed
4.3EPSS 0.001
CVE-2013-0567
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-2987, CVE-2013-3020, CVE-2013-0568, and CVE-2013-0475.
Published 2013-07-03 · Modified
4.0EPSS 0.011
CVE-2013-0479
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not properly restrict file types and extensions, which allows remote authenticated users to bypass intended access restrictions via a crafted filename.
Published 2013-07-03 · Modified
4.0EPSS 0.010
CVE-2013-0463
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-2985, CVE-2013-2987, CVE-2013-3020, CVE-2013-0568, CVE-2013-0475, and CVE-2013-0567.
Published 2013-07-03 · Modified
4.0EPSS 0.009
CVE-2013-0475
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-2987, CVE-2013-3020, CVE-2013-0568, and CVE-2013-0567.
Published 2013-07-03 · Modified
4.0EPSS 0.009
CVE-2013-0568
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-2987, CVE-2013-3020, CVE-2013-0475, and CVE-2013-0567.
Published 2013-07-03 · Modified
4.0EPSS 0.009
CVE-2013-2985
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2987, CVE-2013-3020, CVE-2013-0568, CVE-2013-0475, and CVE-2013-0567.
Published 2013-07-03 · Modified
4.0EPSS 0.009
CVE-2013-2987
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-3020, CVE-2013-0568, CVE-2013-0475, and CVE-2013-0567.
Published 2013-07-03 · Modified
4.0EPSS 0.009
CVE-2013-3020
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-2987, CVE-2013-0568, CVE-2013-0475, and CVE-2013-0567.
Published 2013-07-03 · Modified
4.0EPSS 0.009
CVE-2013-0456
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to hijack sessions via a modified cookie path.
Published 2013-07-03 · Modified
4.0EPSS 0.008
CVE-2025-1348
IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure
Published 2025-06-18 · Analyzed
4.0EPSS 0.001
CVE-2023-42010
IBM Sterling B2B Integrator Standard Edition information disclosure
Published 2024-07-17 · Modified
3.7EPSS 0.003
CVE-2019-4146
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 could allow an authenticated user to obtain sensitive document information under unusual circumstances. IBM X-Force ID: 158401.
Published 2019-04-25 · Modified
3.5EPSS 0.011
CVE-2013-5405
Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters.
Published 2013-12-21 · Modified
3.5EPSS 0.009
CVE-2013-5406
Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters, leading to improper interaction with the Windows MHTML protocol handler.
Published 2013-12-21 · Modified
3.5EPSS 0.009
CVE-2015-4992
IBM Sterling B2B Integrator 5.2 before 5020500_8 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.
Published 2015-10-05 · Modified
3.5EPSS 0.008
← Prev5 / 6Next →