CVE-2024-49807
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Summary
CVE-2024-49807 is a stored cross-site scripting (XSS) vulnerability affecting IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition. Authenticated users can exploit this issue by embedding malicious JavaScript code in the Web UI. The outcome could be altering the intended functionality, potentially leading to credential disclosure within a secure session. This vulnerability poses a significant security risk, as attackers may gain unauthorized access to sensitive business information. IBM strongly advises users to update their software to a non-vulnerable version as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.