Impact
IBM Sterling B2B Integrator and IBM Sterling File Gateway are affected by a stored cross‑site scripting vulnerability. A privileged user can embed arbitrary JavaScript code into the Web UI, which may alter the intended functionality of the application. This flaw can lead to credential disclosure within a trusted session.
Affected Systems
IBM’s Sterling B2B Integrator and Sterling File Gateway products are impacted. Affected releases span from version 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 for both product lines.
Risk and Exploitability
The CVSS base score of 5.5 indicates a moderate severity, while the EPSS score of less than 1% signals a low exploitation probability. Because the flaw requires privileged access to the Web UI, successful exploitation is limited to users with administrator or similar rights. The vulnerability is not documented in the CISA KEV catalog, suggesting it has not been widely exploited yet.
OpenCVE Enrichment