CVE-2019-4387: SQL Injection
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.2.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 162715.
Other sources
IBM Sterling B2B Integrator Standard Edition is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4387?
CVE-2019-4387 is considered a high severity vulnerability due to its potential for SQL injection and unauthorized access to the database.
How do I fix CVE-2019-4387?
To fix CVE-2019-4387, apply the latest security patches provided by IBM for the Sterling B2B Integrator.
What types of attacks are possible with CVE-2019-4387?
With CVE-2019-4387, an attacker could execute SQL injection attacks to view, modify, or delete data in the back-end database.
Which versions of IBM Sterling B2B Integrator are affected by CVE-2019-4387?
CVE-2019-4387 affects IBM Sterling B2B Integrator versions from 6.0.0.0 to 6.0.2.0 inclusive.
Is CVE-2019-4387 exploitable remotely?
Yes, CVE-2019-4387 can be exploited remotely by sending specially-crafted SQL statements to the vulnerable application.