Ibm · Ibm Sterling B2B Integrator · CVE-2021-20571
Name of the Vulnerable Software and Affected Versions:
IBM Sterling B2B Integrator versions 5.2.0.0 through 6.1.1.0
Description:
The issue allows users to embed arbitrary JavaScript code in the Web UI, altering the intended functionality and potentially leading to credentials disclosure within a trusted session. This is due to a stored cross-site scripting vulnerability.
Recommendations:
For IBM Sterling B2B Integrator versions 5.2.0.0 through 6.1.1.0, update to a version outside of this range to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the Web UI to minimize the risk of exploitation.