First published: Mon Feb 17 2020(Updated: )
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 167880.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM B2B Sterling Integrator | <=5.2.0.0 - 6.0.3.0 | |
IBM B2B Sterling Integrator | >=5.2.0.0<=5.2.6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4597 has a high severity rating due to the potential for remote SQL injection attacks.
To fix CVE-2019-4597, upgrade your IBM Sterling B2B Integrator to version 5.2.6.6 or later.
CVE-2019-4597 affects IBM Sterling B2B Integrator versions from 5.2.0.0 to 5.2.6.5.
CVE-2019-4597 is classified as an SQL injection vulnerability.
Any organization using the vulnerable versions of IBM Sterling B2B Integrator could be impacted by CVE-2019-4597.