Description
IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
Low
Affected products
- ibm / IBM Watson Speech Services Cartridge4.0.0 – 5.3.1
- ibm / sterling_b2b_integrator6.2.1.0 – 6.2.1.1_2
- ibm / sterling_b2b_integrator6.2.2.0 – 6.2.2.0_1
- ibm / sterling_file_gateway6.2.2.0 – 6.2.2.0_1
- ibm / sterling_file_gateway6.2.1.0 – 6.2.1.1_2
- ibm / watson_speech_services_cartridge4.0.0 – 5.3.1
- ibm / watson_speech_services_cartridge5.3.1 – 5.3.1
References
Updated 11m ago · 8 sources