First published: Mon Feb 17 2020(Updated: )
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 167881.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM B2B Sterling Integrator | <=5.2.0.0 - 6.0.3.0 | |
IBM B2B Sterling Integrator | >=5.2.0.0<=5.2.6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4598 has a medium severity level allowing for potential unauthorized database access.
To fix CVE-2019-4598, apply the relevant patches provided by IBM for Sterling B2B Integrator versions 5.2.0.0 through 5.2.6.5.
CVE-2019-4598 affects IBM Sterling B2B Integrator versions 5.2.0.0 through 5.2.6.5.
Yes, CVE-2019-4598 can be exploited remotely by an attacker sending specially-crafted SQL statements.
CVE-2019-4598 is classified as an SQL injection vulnerability.