CVE-2024-40696
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Published Jan 31, 2025
CWE ID 79
Summary
CVE-2024-40696 is a cross-site scripting (XSS) vulnerability affecting IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition. A privileged user can exploit this weakness by embedding arbitrary JavaScript code into the Web UI. This code can alter the intended functionality, posing a threat for potential credentials disclosure within a trusted session. This vulnerability puts sensitive business data at risk, emphasizing the importance of applying the available patch promptly.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.