First published: Fri Aug 02 2019(Updated: )
IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 158413.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling File Gateway | >=2.2<=6.0.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4147 is a SQL injection vulnerability in IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0.
CVE-2019-4147 has a severity score of 7.2, which is considered high.
CVE-2019-4147 allows a remote attacker to send specially-crafted SQL statements that could enable them to view, add, modify, or delete information in the back-end database.
IBM Sterling File Gateway versions 2.2.0.0 through 6.0.1.0 are affected by CVE-2019-4147.
To fix CVE-2019-4147, apply the necessary security patches provided by IBM. Implement input validation and parameterized queries to prevent SQL injection attacks.