IBM Support

IT24693: CROSS-SITE SCRIPTING ISSUE IN IBM STERLING B2B INTEGRATOR DASHBOARD REPORTS

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • In IBM Sterling B2B Integrator dashboard, when creating a report
    with a name including XSS payload like
    <script>alert(1)</script> results in an XSS security
    vulnerability.
    
    1. Create a report configuration with Operations -> Reports then
    Report Configuration.
    2. Change NAME column to <script>alert(1)</script> in RPT_CONFIG
    table for the entry created from step 1.
    3. Set up an interceptor like Burp.
    4. Go to Operations -> Reports then click "Go" button for List.
    5. Burp will intercepts the request. Change the parameter alpha
    to <script>alert(1)</script>.
    6. Without the fix, an alert box will appear. With the fix,
    there will be no alert.
    

Local fix

  • RTC: 563331
    

Problem summary

  • Users Affected:
    All
    
    Problem Description:
    Reflected Cross-site Scripting (XSS) issue dashboard reports.
    
    Platforms Affected:
    All
    

Problem conclusion

  • Resolution Summary:
    
    A code fix is provided.
    
    Delivered In:
    5020603_6
    

Temporary fix

  • No
    

Comments

APAR Information

  • APAR number

    IT24693

  • Reported component name

    STR B2B INTEGRA

  • Reported component ID

    5725D0600

  • Reported release

    526

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2018-04-20

  • Closed date

    2018-07-09

  • Last modified date

    2018-07-15

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    STR B2B INTEGRA

  • Fixed component ID

    5725D0600

Applicable component levels

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS3JSW","label":"Sterling B2B Integrator"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"5.2.6","Line of Business":{"code":"LOB59","label":"Sustainability Software"}}]

Document Information

Modified date:
11 September 2023