First published: Wed Jul 03 2013(Updated: )
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2012-5766.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM B2B Sterling Integrator | =5.1 | |
IBM B2B Sterling Integrator | =5.2 | |
IBM Sterling File Gateway | =2.1 | |
IBM Sterling File Gateway | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0560 is rated as a medium severity vulnerability that allows remote authenticated users to execute arbitrary SQL commands.
To fix CVE-2013-0560, update IBM Sterling B2B Integrator to version 5.3 or later and IBM Sterling File Gateway to version 2.3 or later.
CVE-2013-0560 affects IBM Sterling B2B Integrator versions 5.1 and 5.2, and IBM Sterling File Gateway versions 2.1 and 2.2.
Yes, CVE-2013-0560 can be exploited remotely by authenticated users to execute SQL commands.
CVE-2013-0560 allows attackers to perform SQL injection attacks that can compromise data integrity and confidentiality.