First published: Wed Jul 03 2013(Updated: )
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to execute arbitrary SQL commands via vectors involving the RNVisibility page and unspecified screens, a different vulnerability than CVE-2013-0560.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM B2B Sterling Integrator | =5.1 | |
IBM B2B Sterling Integrator | =5.2 | |
IBM Sterling File Gateway | =2.1 | |
IBM Sterling File Gateway | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5766 is considered a high severity vulnerability due to its potential for remote authenticated users to execute arbitrary SQL commands.
To fix CVE-2012-5766, update to IBM Sterling B2B Integrator version 5.3 or later or IBM Sterling File Gateway version 2.3 or later.
CVE-2012-5766 affects IBM Sterling B2B Integrator versions 5.1 and 5.2, and IBM Sterling File Gateway versions 2.1 and 2.2.
CVE-2012-5766 can be exploited by remote authenticated users who have access to the affected systems.
CVE-2012-5766 is classified as an SQL injection vulnerability, which allows for arbitrary SQL command execution.