Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
105 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.9) | 0.26% | — | IBM Sterling B2B IntegratorIBM Sterling File Gateway | 4/9/2025 | 17/6/2026 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 could disclose sensitive system information about the server to a privileged user that could aid in further attacks against the system. | |
| Analizada | Media (6.5) | 0.25% | — | IBM Sterling B2B IntegratorIBM Sterling File Gateway | 19/8/2025 | 17/6/2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6.2.0.4, and 6.2.1.0 could disclose sensitive server information to an unauthorized user that could aid in further attacks against the system. | |
| Analizada | Media (5.4) | 0.24% | — | IBM Sterling B2B IntegratorIBM Sterling File Gateway | 19/8/2025 | 17/6/2026 | IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File Gateway 6.2.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted… | |
| Analizada | Media (6.1) | 0.21% | — | IBM Sterling B2B IntegratorIBM Sterling File Gateway | 18/7/2025 | 17/6/2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.4 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser. | |
| Analizada | Media (5.4) | 0.19% | — | IBM Sterling B2B IntegratorIBM Sterling File Gateway | 8/7/2025 | 17/6/2026 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the… | |
| Analizada | Media (4.3) | 0.24% | — | IBM Sterling File Gateway | 8/7/2025 | 17/6/2026 | IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 could disclose sensitive installation directory information to an authenticated user that could be used in further attacks against the system. | |
| Analizada | Media (5.4) | 0.19% | — | IBM Sterling B2B IntegratorIBM Sterling File Gateway | 8/7/2025 | 17/6/2026 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended… | |
| Analizada | Media (4.8) | 0.21% | — | IBM Sterling B2B IntegratorIBM Sterling File Gateway | 18/6/2025 | 17/6/2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to… | |
| Analizada | Media (4) | 0.14% | — | IBM Sterling B2B IntegratorIBM Sterling File Gateway | 18/6/2025 | 17/6/2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 could allow a local user to obtain sensitive information from a user’s web browser cache due to not using a suitable caching policy. | |
| Analizada | Media (4.3) | 0.14% | — | IBM Sterling B2B IntegratorIBM Sterling File Gateway | 18/6/2025 | 17/6/2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | |
| Analizada | Media (5.4) | 0.20% | — | IBM Sterling B2B IntegratorIBM Sterling File Gateway | 18/6/2025 | 17/6/2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to… | |
| Analizada | Media (5.3) | 0.29% | — | IBM Sterling File Gateway | 10/3/2025 | 17/6/2026 | IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure the installation path of the server which could aid in further attacks against the system. | |
| Modificada | Media (4.3) | 0.24% | — | IBM Sterling File Gateway | 27/1/2025 | 17/6/2026 | IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to perform unauthorized actions to another user's data due to improper access controls. | |
| Analizada | Media (5.4) | 0.23% | — | IBM Sterling File Gateway | 27/1/2025 | 17/6/2026 | IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (4.3) | 0.29% | — | IBM Sterling File Gateway | 27/1/2025 | 17/6/2026 | IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to enumerate usernames due to an observable discrepancy in request responses. | |
| Analizada | Media (5.4) | 0.32% | — | IBM Sterling File Gateway | 12/4/2024 | 17/6/2026 | IBM Sterling File Gateway 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted… | |
| Modificada | Media (5.3) | 0.94% | — | IBM Sterling File Gateway | 16/8/2022 | 17/6/2026 | IBM Sterling File Gateway 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID:… | |
| Modificada | Media (6.5) | 0.74% | — | IBM Sterling File Gateway | 8/10/2021 | 17/6/2026 | IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensitive information due to improper permission control. IBM X-Force ID: 186090. | |
| Modificada | Media (4.3) | 0.98% | — | IBM Sterling File Gateway | 7/10/2021 | 17/6/2026 | IBM Sterling File Gateway 6.0.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199170. | |
| Modificada | Alta (8.8) | 0.40% | — | IBM Sterling File Gateway | 7/10/2021 | 17/6/2026 | IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 197790. | |
| Modificada | Media (6.1) | 0.64% | — | IBM Sterling File Gateway | 7/10/2021 | 17/6/2026 | IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 197503. | |
| Modificada | Media (6.5) | 0.48% | — | IBM Sterling File Gateway | 7/10/2021 | 17/6/2026 | IBM Sterling File Gateway User Interface 2.2.0.0 through 6.1.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 196944. | |
| Modificada | Media (4.3) | 0.73% | — | IBM Sterling File Gateway | 23/9/2021 | 17/6/2026 | IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote authenciated user to obtain sensitive information. By sending a specially crafted request, the user could disclose a valid filepath on the server which could be used in further attacks against the system. IBM X-Force ID: 199234. | |
| Modificada | Media (4.3) | 0.98% | — | IBM Sterling File Gateway | 23/9/2021 | 17/6/2026 | IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 197667. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Sterling File Gateway | 23/9/2021 | 17/6/2026 | IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 197666. |