vendor:
IBM Sterling B2B Integrator
by:
Vikas Khanna
7.5
CVSS
HIGH
Persistent Cross Site Scripting
79
CWE
Product Name: IBM Sterling B2B Integrator
Affected Version From: IBM Sterling B2B Integrator 5.2.0.1
Affected Version To: IBM Sterling B2B Integrator 5.2.6.3
Patch Exists: NO
Related CWE: CVE-2018-1513 & CVE-2018-1563
CPE: a:ibm:sterling_b2b_integrator
Platforms Tested:
IBM Sterling B2B Integrator persistent cross-site scripting
The vulnerability allows an attacker to insert malicious JavaScript code in the fname and lname parameters, which gets executed when the Performance Tuning module of IBM Sterling B2B Integrator is accessed. This can lead to various attacks such as stealing sensitive information or performing actions on behalf of the user.
Mitigation:
Apply the vendor-provided patch or upgrade to IBM Sterling B2B Integrator version 5.2.6.4 or later. Avoid giving unnecessary privileges to non-admin users.