
CVE-2019-4063
https://notcve.org/view.php?id=CVE-2019-4063
05 Mar 2019 — IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 Standard Edition could allow highly sensitive information to be transmitted in plain text. An attacker could obtain this information using man in the middle techniques. IBM X-ForceID: 157008. IBM Sterling B2B Integrator, desde la versión 5.2.0.1 hasta la 6.0.0.0, en su edición estándar, podría permitir que se transmita información sensible en texto plano. Un atacante podría obtener esta información empleando técnicas Man-in-the-Middle (MitM). • http://www.securityfocus.com/bid/107310 • CWE-319: Cleartext Transmission of Sensitive Information •

CVE-2018-1800
https://notcve.org/view.php?id=CVE-2018-1800
20 Sep 2018 — IBM Sterling B2B Integrator Standard Edition 5.2.6.0 and 6.2.6.1 could allow a local user to obtain highly sensitive information during a short time period when installation is occurring. IBM X-Force ID: 149607. IBM Sterling B2B Integrator Standard Edition 5.2.6.0 y 6.2.6.1 podría permitir que un usuario local obtenga información altamente sensible durante un corto periodo de tiempo mientras se está instalando. IBM X-Force ID: 149607. • https://exchange.xforce.ibmcloud.com/vulnerabilities/149607 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2018-1718
https://notcve.org/view.php?id=CVE-2018-1718
31 Jul 2018 — IBM Sterling B2B Integrator Standard Edition 5.2.0.1 - 5.2.6.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147166. IBM Sterling B2B Integrator Standard Edition 5.2.0.1 - 5.2.6.3 es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en ... • http://www.securityfocus.com/bid/104938 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2018-1513 – IBM Sterling B2B Integrator 5.2.0.1/5.2.6.3 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2018-1513
23 Jul 2018 — IBM Sterling B2B Integrator Standard Edition 5.2.0 through 5.2.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141551. IBM Sterling B2B Integrator Standard Edition de la versión 5.2.0 a la 5.2.6 es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript... • https://packetstorm.news/files/id/148882 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2018-1679
https://notcve.org/view.php?id=CVE-2018-1679
20 Jul 2018 — IBM Sterling B2B Integrator Standard Edition 5.2 through 5.2.6 could allow an unauthenticated user to obtain sensitive information that could be used in further attacks against the system. IBM X-Force ID: 145180. IBM Sterling B2B Integrator Standard Edition desde la versión 5.2 hasta la 5.2.6 podría permitir que un usuario no autenticado obtenga información sensible que podría emplearse en más ataques contra el sistema. IBM X-Force ID: 145180. • http://www.ibm.com/support/docview.wss?uid=ibm10716747 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2018-1564
https://notcve.org/view.php?id=CVE-2018-1564
20 Jul 2018 — IBM Sterling B2B Integrator Standard Edition 5.2 through 5.2.6 could allow a local user with administrator privileges to obtain user passwords found in debugging messages. IBM X-Force ID: 142968. IBM Sterling B2B Integrator Standard Edition desde la versión 5.2 hasta la 5.2.6 podría permitir que un usuario local con privilegios de administrador obtenga contraseñas de usuario halladas en mensajes de depuración. IBM X-Force ID: 142968. • http://www.ibm.com/support/docview.wss?uid=ibm10716747 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-1633
https://notcve.org/view.php?id=CVE-2017-1633
20 Jul 2018 — IBM Sterling B2B Integrator 5.2 through 5.2.6 could allow an authenticated attacker to obtain sensitive variable name information using specially crafted HTTP requests. IBM X-Force ID: 133180. IBM Sterling B2B Integrator desde la versión 5.2 hasta la 5.2.6 podría permitir que un atacante autenticado obtenga información sensible de nombres de variables mediante peticiones HTTP especialmente manipuladas. IBM X-Force ID: 133180. • http://www.ibm.com/support/docview.wss?uid=ibm10716747 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2018-1563 – IBM Sterling B2B Integrator 5.2.0.1/5.2.6.3 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2018-1563
20 Jul 2018 — IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142967. IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway desde la versión 2.2.0 hasta la 2.2.6) es vulnerable a Cross-Site Scripting (XSS). Esta vu... • https://packetstorm.news/files/id/148882 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-1496
https://notcve.org/view.php?id=CVE-2017-1496
31 Jul 2017 — IBM Sterling B2B Integrator Standard Edition 5.2.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128694. IBM Sterling B2B Integrator Standard Edition versión 5.2.x es vulnerable a ataque de tipo cross-site-scripting (XSS). Esta vulnerabilidad permite a los usuarios insertar código JavaScript arbitrario en la... • http://www.ibm.com/support/docview.wss?uid=swg22006175 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-6020
https://notcve.org/view.php?id=CVE-2016-6020
01 Feb 2017 — IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM Sterling B2B Integrator Standard Edition ... • http://www.ibm.com/support/docview.wss?uid=swg21995794 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •