Description
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected products
- ibm / sterling_b2b_integrator6.2.1.0 – 6.2.1.0
- ibm / sterling_b2b_integrator6.2.1.1_2 – 6.2.1.1_2
- ibm / sterling_b2b_integrator6.2.2.0 – 6.2.2.0
- ibm / sterling_b2b_integrator6.2.2.0_1 – 6.2.2.0_1
- ibm / sterling_b2b_integrator6.2.0.5_2 – 6.2.0.5_2
- ibm / sterling_b2b_integrator6.2.0.0 – 6.2.0.5_2
- ibm / sterling_b2b_integrator6.2.0.0 – 6.2.0.0
- ibm / sterling_file_gateway6.2.0.0 – 6.2.0.5_2
- ibm / sterling_file_gateway6.2.0.0 – 6.2.0.0
- ibm / sterling_file_gateway6.2.0.5_2 – 6.2.0.5_2
- ibm / sterling_file_gateway6.2.1.0 – 6.2.1.0
- ibm / sterling_file_gateway6.2.1.1_2 – 6.2.1.1_2
- ibm / sterling_file_gateway6.2.2.0 – 6.2.2.0
- ibm / sterling_file_gateway6.2.2.0_1 – 6.2.2.0_1
References
Updated 46m ago · 8 sources