CVE-2017-1496

Description

IBM Sterling B2B Integrator Standard Edition 5.2.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128694.

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.198

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 5.2Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 5.2.4Windows
Vulnerabilities CVE-2014-6146,CVE-2014-6199,CVE-2016-6020,CVE-2017-1496 are affected in IBM Sterling B2B Integrator 5.2.1Windows
Vulnerabilities CVE-2014-6146,CVE-2014-6199,CVE-2016-6020,CVE-2017-1496 are affected in IBM Sterling B2B Integrator 5.2.2Windows
Vulnerabilities CVE-2016-6020,CVE-2017-1496 are affected in IBM Sterling B2B Integrator 5.2.5Windows
Vulnerabilities CVE-2016-6020,CVE-2017-1496,CVE-2018-1513 are affected in IBM Sterling B2B Integrator 5.2.6Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 5.2.3Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 5.2.6Windows
Vulnerabilities CVE-2016-6020,CVE-2017-1496,CVE-2017-6168 are affected in IBM Sterling B2B Integrator 5.2.5Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234