Cross-Site Scripting Vulnerability in IBM Sterling B2B Integrator and File Gateway
CVE-2023-40693
5.4MEDIUM
What is CVE-2023-40693?
IBM Sterling B2B Integrator and IBM Sterling File Gateway are susceptible to cross-site scripting (XSS) attacks where arbitrary JavaScript code can be injected within the web interface. This vulnerability may allow an attacker to manipulate the interface and potentially disclose sensitive user credentials while a user is in a trusted session. It is crucial to apply provided patches to mitigate risks associated with this vulnerability.
Affected Version(s)
Sterling B2B Integrator 6.1.0.0 <= 6.1.2.7_2
Sterling B2B Integrator 6.2.0.0 <= 6.2.0.5_1
Sterling B2B Integrator 6.2.1.0 <= 6.2.1.1_1