CVE-2024-31914

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
References
Link Resource
https://www.ibm.com/support/pages/node/7176081 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:standard:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:standard:*:*:*
OR cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

20 Jun 2025, 18:10

Type Values Removed Values Added
Summary
  • (es) IBM Sterling B2B Integrator Standard Edition 6.0.0.0 a 6.1.2.5 y 6.2.0.0 a 6.2.0.2 es vulnerable a cross site scripting almacenado. Esta vulnerabilidad permite a los usuarios incorporar código JavaScript arbitrario en la interfaz de usuario web, alterando así la funcionalidad prevista y pudiendo provocar la divulgación de credenciales dentro de una sesión de confianza.
First Time Linux
Ibm sterling B2b Integrator
Ibm aix
Microsoft
Ibm
Microsoft windows
Linux linux Kernel
References () https://www.ibm.com/support/pages/node/7176081 - () https://www.ibm.com/support/pages/node/7176081 - Vendor Advisory
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:standard:*:*:*

06 Jan 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-06 16:15

Updated : 2025-06-20 18:10


NVD link : CVE-2024-31914

Mitre link : CVE-2024-31914

CVE.ORG link : CVE-2024-31914


JSON object : View

Products Affected

microsoft

  • windows

linux

  • linux_kernel

ibm

  • aix
  • sterling_b2b_integrator
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')