CVE-2024-49807

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Jan 31, 2025
CWE ID 79

Summary

CVE-2024-49807 is a stored cross-site scripting (XSS) vulnerability affecting IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition. Authenticated users can exploit this issue by embedding malicious JavaScript code in the Web UI. The outcome could be altering the intended functionality, potentially leading to credential disclosure within a secure session. This vulnerability poses a significant security risk, as attackers may gain unauthorized access to sensitive business information. IBM strongly advises users to update their software to a non-vulnerable version as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share