CVE-2020-4655: SQL Injection
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 186091.
Other sources
IBM Sterling B2B Integrator Standard Edition is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4655?
CVE-2020-4655 has a medium severity rating due to the potential for SQL injection attacks.
How do I fix CVE-2020-4655?
To fix CVE-2020-4655, apply the patches provided by IBM for affected versions of Sterling B2B Integrator.
What versions of IBM Sterling B2B Integrator are affected by CVE-2020-4655?
CVE-2020-4655 affects IBM Sterling B2B Integrator versions 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2.
Can CVE-2020-4655 be exploited remotely?
Yes, CVE-2020-4655 can be exploited remotely by attackers sending specially crafted SQL statements.
What consequences can arise from exploiting CVE-2020-4655?
Exploiting CVE-2020-4655 may allow an attacker to view, add, modify, or delete information in the back-end database.