Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Aldi Satria

#47197of 53,639
5.4Total CVSS
Vulnerabilities · 1
PT-2025-2594
5.4
2025-01-31
Ibm · Ibm Sterling B2B Integrator · CVE-2024-40696
**Name of the Vulnerable Software and Affected Versions** IBM Sterling B2B Integrator versions 6.0.0.0 through 6.1.2.5 IBM Sterling B2B Integrator versions 6.2.0.0 through 6.2.0.3 **Description** The issue allows a privileged user to embed arbitrary JavaScript code in the Web UI, altering the intended functionality and potentially leading to credentials disclosure within a trusted session. This is due to a cross-site scripting vulnerability. **Recommendations** For versions 6.0.0.0 through 6.1.2.5, update to a version outside of this range to mitigate the risk. For versions 6.2.0.0 through 6.2.0.3, update to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting access to the Web UI to minimize the risk of exploitation.