Impact
This vulnerability is a cross‑site scripting flaw in IBM Sterling B2B Integrator and IBM Sterling File Gateway Web UI. An authenticated user can inject arbitrary JavaScript into the Web UI, enabling tampering of the interface and potentially exposing credentials from a trusted session. The flaw corresponds to CWE‑79, reflecting insufficient sanitization of user‑controlled input.
Affected Systems
IBM Sterling B2B Integrator and IBM Sterling File Gateway versions 6.2.2.0 and 6.2.2.0_1 are affected. These versions are listed in the vendor’s advisory and support documents.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score is <1%, indicating a very low but nonzero likelihood of exploitation, and the vulnerability is not yet listed in CISA’s KEV catalog. The attack vector requires an authenticated session, so the attacker must have valid credentials to access the Web UI. With the injected script the attacker could manipulate the interface, relay sensitive information, and possibly compromise session integrity.
OpenCVE Enrichment