CVE-2021-20375
https://notcve.org/view.php?id=CVE-2021-20375
07 Oct 2021 — IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to intercept and replace a message sent by another user due to improper access controls. IBM X-Force ID: 195567. IBM Sterling File Gateway versiones 2.2.0.0 hasta 6.1.1.0, podría permitir a un usuario autenticado interceptar y sustituir un mensaje enviado por otro usuario debido a controles de acceso inapropiados. IBM X-Force ID: 195567 • https://exchange.xforce.ibmcloud.com/vulnerabilities/195567 •
CVE-2021-20372
https://notcve.org/view.php?id=CVE-2021-20372
07 Oct 2021 — IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote authenticated user to cause a denial of another user's service due to insufficient permission checking. IBM X-Force ID: 195518. IBM Sterling File Gateway versiones 2.2.0.0 hasta 6.1.1.0, podría permitir a un usuario autenticado remoto causar una denegación de servicio de otro usuario debido a una comprobación de permisos insuficiente. IBM X-Force ID: 195518 • https://exchange.xforce.ibmcloud.com/vulnerabilities/195518 •
CVE-2021-38925
https://notcve.org/view.php?id=CVE-2021-38925
06 Oct 2021 — IBM Sterling B2B Integrator Standard Edition 5.2.0. 0 through 6.1.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210171. IBM Sterling B2B Integrator Standard Edition versiones 5.2.0. 0 hasta 6.1.1.0, usa algoritmos criptográficos más débiles de lo esperado que podrían permitir a un atacante descifrar información altamente confidencial. IBM X-Force ID: 210171 • https://exchange.xforce.ibmcloud.com/vulnerabilities/210171 • CWE-326: Inadequate Encryption Strength •
CVE-2021-29903
https://notcve.org/view.php?id=CVE-2021-29903
06 Oct 2021 — IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 207506. IBM Sterling B2B Integrator Standard Edition versiones 5.2.6.0 hasta 6.1.1.0, es vulnerable a una inyección SQL. Un atacante remoto podría enviar sentencias SQL especialmente diseñadas, que podrían permitir al atacante visua... • https://exchange.xforce.ibmcloud.com/vulnerabilities/207506 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2021-29855
https://notcve.org/view.php?id=CVE-2021-29855
06 Oct 2021 — IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 205684. IBM Sterling B2B Integrator Standard Edition versiones 5.2.0.0 hasta 6.1.1.0, es vulnerable a un ataque de tipo cross-site scripting. Esta vulnerabilidad permite a usuarios insertar códi... • https://exchange.xforce.ibmcloud.com/vulnerabilities/205684 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-29837
https://notcve.org/view.php?id=CVE-2021-29837
06 Oct 2021 — IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 204913. IBM Sterling B2B Integrator Standard Edition versiones 5.2.0.0 hasta 6.1.1.0, es vulnerable a un ataque de tipo cross-site request forgery, que podría permitir a un atacante ejecutar acciones maliciosas y no autorizadas transmitidas desde un usuario ... • https://exchange.xforce.ibmcloud.com/vulnerabilities/204913 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2021-29836
https://notcve.org/view.php?id=CVE-2021-29836
06 Oct 2021 — IBM Sterling B2B Integrator Standard Edition 5.2.0.0. through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204912. IBM Sterling B2B Integrator Standard Edition versiones 5.2.0.0. hasta 6.1.1.0, es vulnerable a un ataque de tipo cross-site scripting. Esta vulnerabilidad permite a usuarios insertar có... • https://exchange.xforce.ibmcloud.com/vulnerabilities/204912 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-29798
https://notcve.org/view.php?id=CVE-2021-29798
06 Oct 2021 — IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 203734. IBM Sterling B2B Integrator Standard Edition versiones 6.0.0.0 hasta 6.1.1.0, es vulnerable a una inyección SQL. Un atacante remoto podría enviar sentencias SQL especialmente diseñadas, lo que podría permitir al atacante vis... • https://exchange.xforce.ibmcloud.com/vulnerabilities/203734 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2021-29764
https://notcve.org/view.php?id=CVE-2021-29764
06 Oct 2021 — IBM Sterling B2B Integrator 5.2.0.0 through 6.1.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 202268. IBM Sterling B2B Integrator versiones 5.2.0.0 hasta la versión 6.1.1.0 es vulnerable al cross-site scripting almacenado. Esta vulnerabilidad permite a los usuarios incrustar código JavaScript arbi... • https://exchange.xforce.ibmcloud.com/vulnerabilities/202268 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-29761
https://notcve.org/view.php?id=CVE-2021-29761
06 Oct 2021 — IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensitive information from the dashboard that they should not have access to. IBM X-Force ID: 202265. IBM Sterling B2B Integrator Standard Edition versiones 5.2.0.0 hasta 6.1.1.0, podría permitir a un usuario autenticado conseguir información confidencial del tablero de mandos a la que no debería tener acceso. IBM X-Force ID: 202265 • https://exchange.xforce.ibmcloud.com/vulnerabilities/202265 •