Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Dinesh Ponnudurai

#46918of 53,633
5.4Total CVSS
Vulnerabilities · 1
PT-2021-14047
5.4
2021-10-07
Ibm · Ibm Sterling B2B Integrator · CVE-2021-20571
Name of the Vulnerable Software and Affected Versions: IBM Sterling B2B Integrator versions 5.2.0.0 through 6.1.1.0 Description: The issue allows users to embed arbitrary JavaScript code in the Web UI, altering the intended functionality and potentially leading to credentials disclosure within a trusted session. This is due to a stored cross-site scripting vulnerability. Recommendations: For IBM Sterling B2B Integrator versions 5.2.0.0 through 6.1.1.0, update to a version outside of this range to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the Web UI to minimize the risk of exploitation.