CVE-2019-4147: SQL Injection
IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 158413.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-4147?
CVE-2019-4147 is a SQL injection vulnerability in IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0.
How severe is CVE-2019-4147?
CVE-2019-4147 has a severity score of 7.2, which is considered high.
How does CVE-2019-4147 affect IBM Sterling File Gateway?
CVE-2019-4147 allows a remote attacker to send specially-crafted SQL statements that could enable them to view, add, modify, or delete information in the back-end database.
Which version of IBM Sterling File Gateway is affected by CVE-2019-4147?
IBM Sterling File Gateway versions 2.2.0.0 through 6.0.1.0 are affected by CVE-2019-4147.
How can I fix or mitigate CVE-2019-4147?
To fix CVE-2019-4147, apply the necessary security patches provided by IBM. Implement input validation and parameterized queries to prevent SQL injection attacks.