First published: Sat Dec 21 2013(Updated: )
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling B2B Integrator | =5.2 | |
IBM Sterling File Gateway | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5409 is considered a medium severity vulnerability due to its potential for remote SQL injection by authenticated users.
To mitigate CVE-2013-5409, users should upgrade IBM Sterling B2B Integrator to version 5.2.6 or higher and IBM Sterling File Gateway to version 2.2.3 or higher.
CVE-2013-5409 affects users of IBM Sterling B2B Integrator version 5.2 and IBM Sterling File Gateway version 2.2.
CVE-2013-5409 allows attackers to execute arbitrary SQL commands, which can compromise database integrity and confidentiality.
There are no published workarounds for CVE-2013-5409; upgrading to secure versions is the recommended solution.