CVE-2018-1563 – IBM Sterling B2B Integrator 5.2.0.1/5.2.6.3 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2018-1563
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142967. IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway desde la versión 2.2.0 hasta la 2.2.6) es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera las funcionalidades previstas. • https://www.exploit-db.com/exploits/45190 http://www.ibm.com/support/docview.wss?uid=ibm10717031 http://www.securityfocus.com/bid/104910 https://exchange.xforce.ibmcloud.com/vulnerabilities/142967 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-1575
https://notcve.org/view.php?id=CVE-2017-1575
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) uses weaker than expected cryptographic algorithms that could allow a local attacker to decrypt highly sensitive information. IBM X-Force ID: 132032. IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway desde la versión 2.2.0 hasta la 2.2.6) emplea algoritmos criptográficos más débiles de lo esperado que podrían permitir que un atacante local descifre información altamente sensible. IBM X-Force ID: 132032. • http://www.ibm.com/support/docview.wss?uid=ibm10716997 http://www.securityfocus.com/bid/104885 https://exchange.xforce.ibmcloud.com/vulnerabilities/132032 • CWE-327: Use of a Broken or Risky Cryptographic Algorithm •
CVE-2014-0912
https://notcve.org/view.php?id=CVE-2014-0912
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to obtain sensitive product information via vectors related to an error page. IBM X-Force ID: 92072. IBM Sterling B2B Integrator 5.1 y 5.2 y Sterling File Gateway 2.1 y 2.2 permiten que atacantes remotos obtengan información sensible del producto mediante vectores relacionados con una página de error. IBM X-Force ID: 92072. • http://www-01.ibm.com/support/docview.wss?uid=swg21674739 https://exchange.xforce.ibmcloud.com/vulnerabilities/92072 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2014-0927
https://notcve.org/view.php?id=CVE-2014-0927
The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to bypass authentication by leveraging knowledge of the port number and webapp path. IBM X-Force ID: 92259. La interfaz de usuario administrativo Active MQ en IBM Sterling B2B Integrator 5.1 y 5.2 y Sterling File Gateway 2.1 y 2.2 permite que atacantes remotos omitan la autenticación aprovechando el conocimiento del número de puerto y la ruta de la webapp. IBM X-Force ID: 92259. • http://www-01.ibm.com/support/docview.wss?uid=swg21674739 https://exchange.xforce.ibmcloud.com/vulnerabilities/92259 • CWE-287: Improper Authentication •
CVE-2017-1550
https://notcve.org/view.php?id=CVE-2017-1550
IBM Sterling File Gateway 2.2 could allow an authenticated user to change other user's passwords. IBM X-Force ID: 131290. IBM Sterling File Gateway 2.2 podría permitir que un usuario autenticado cambie las contraseñas de otros usuarios. IBM X-Force ID: 131290. • http://www.ibm.com/support/docview.wss?uid=swg22010758 http://www.securityfocus.com/bid/102184 https://exchange.xforce.ibmcloud.com/vulnerabilities/131290 •