IBM Sterling B2B Integrator and IBM Sterling File Gateway Cross-Site Scripting
Published Mar 13, 2026
5.4
MEDIUMCVSS 3.1
EPSS 0.21%
Description
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, and 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected products
-
- Version 6.1.0.0StatusaffectedConstraints<=6.1.2.7_2
- Version 6.2.0.0StatusaffectedConstraints<=6.2.0.5_1
- Version 6.2.1.0StatusaffectedConstraints<=6.2.1.1_1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| IBM | Sterling B2B Integrator | n/a |
|
- ≥ 6.1.0.0 · < 6.1.2.8
- ≥ 6.2.0.0 · < 6.2.0.5_2
- ≥ 6.2.1.0 · < 6.2.1.1_2
- ≥ 6.1.0.0 · < 6.1.2.8
- ≥ 6.2.0.0 · < 6.2.0.5_2
- ≥ 6.2.1.0 · < 6.2.1.1_2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Remediation/Fixes Product Version APAR Remediation & Fix IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 - 6.1.2.7_2 IT48832 Apply B2Bi 6.1.2.8, 6.2.0.5_2, 6.2.1.1_2 or 6.2.2.0_1 IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 - 6.2.0.5_1 IT48832 Apply B2Bi 6.2.0.5_2, 6.2.1.1_2 or 6.2.2.0_1 IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.1.0 - 6.2.1.1_1 IT48832 Apply B2Bi 6.2.1.1_2 or 6.2.2.0_1 IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.2.0 IT48832 Apply B2Bi 6.2.2.0_1 The IIM versions of 6.1.2.8, 6.2.0.5_2, 6.2.1.1_2 and 6.2.2.0_1 are available on Fix Central . The container version of 6.1.2.8, 6.2.0.5_2, 6.2.1.1_2 and 6.2.2.0_1 are available in IBM Entitled Registry.
References (1)
- https://www.ibm.com/support/pages/node/7263329 vendor-advisorypatchNot Applicable
| Link | Providers | Tags |
|---|---|---|
| https://www.ibm.com/support/pages/node/7263329 | vendor-advisorypatchNot Applicable |
Change history (0)
No recorded changes yet.