CVE-2019-4258
https://notcve.org/view.php?id=CVE-2019-4258
IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159946. IBM Sterling B2B Integrator versión 6.0.0.0.0 y versión 6.0.0.0.1 Standard Edition es vulnerable a las secuencias de Cross-Site Scripting (XSS). Esta vulnerabilidad permite a los usuarios insertar código JavaScript arbitrario en la interfaz de usuario de la Web, alterando así la funcionalidad prevista que puede conducir a la divulgación de credenciales dentro de una sesión de confianza. • http://www.ibm.com/support/docview.wss?uid=ibm10880591 http://www.securityfocus.com/bid/108188 https://exchange.xforce.ibmcloud.com/vulnerabilities/159946 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2019-4222
https://notcve.org/view.php?id=CVE-2019-4222
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 could allow an authenticated user to view process definition of a business process without permission. IBM X-Force ID: 159231. IBM Sterling B2B Integrator Standard Edition versiones 6.0.0.0.0 y 6.0.0.0.1, podría permitir a un usuario autenticado ver la definición de un proceso empresarial sin permiso. IBM X-Force ID: 159231. • http://www.securityfocus.com/bid/108110 https://exchange.xforce.ibmcloud.com/vulnerabilities/159231 https://www.ibm.com/support/docview.wss?uid=ibm10880595 • CWE-269: Improper Privilege Management •
CVE-2019-4148
https://notcve.org/view.php?id=CVE-2019-4148
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158414. IBM Sterling B2B Integrator Standard Edition versiones 6.0.0.0 y 6.0.0.1 es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite a los usuarios incrustar código JavaScript arbitrario en la interfaz de usuario de la Web, alterando así la funcionalidad prevista que puede conducir a la divulgación de credenciales dentro de una sesión de confianza. • https://exchange.xforce.ibmcloud.com/vulnerabilities/158414 https://www.ibm.com/support/docview.wss?uid=ibm10880591 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2019-4146
https://notcve.org/view.php?id=CVE-2019-4146
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 could allow an authenticated user to obtain sensitive document information under unusual circumstances. IBM X-Force ID: 158401. IBM Sterling B2B Integrator Standard Edition versiones 6.0.0.0 y 6.0.0.1, podría permitir a un usuario autenticado obtener información confidencial de documentos en circunstancias inusuales. IBM X-Force ID: 158401. • http://www.securityfocus.com/bid/108110 https://exchange.xforce.ibmcloud.com/vulnerabilities/158401 https://www.ibm.com/support/docview.wss?uid=ibm10880595 •
CVE-2019-4077
https://notcve.org/view.php?id=CVE-2019-4077
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 157111. IBM Sterling B2B Integrator Standard Edition versiones 6.0.0.0.0 y 6.0.0.0.1 es vulnerable a cross-site scripting. Esta vulnerabilidad permite a los usuarios embeber código JavaScript arbitrario en la interfaz de usuario de la Web, alterando así la funcionalidad prevista que puede conducir a la divulgación de credenciales dentro de una sesión de confianza. • https://exchange.xforce.ibmcloud.com/vulnerabilities/157111 https://www.ibm.com/support/docview.wss?uid=ibm10880591 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •