CVE-2021-29903: SQL Injection
IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 207506.
Other sources
IBM Sterling B2B Integrator Standard Edition is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-29903?
CVE-2021-29903 is a SQL injection vulnerability in IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 6.1.1.0.
How can a remote attacker exploit CVE-2021-29903?
A remote attacker can exploit CVE-2021-29903 by sending specially crafted SQL statements to the affected system.
What can an attacker do if they successfully exploit CVE-2021-29903?
If an attacker successfully exploits CVE-2021-29903, they can view, add, modify, or delete information in the back-end database.
Is there a patch available for CVE-2021-29903?
Yes, IBM has provided a patch for CVE-2021-29903. You can find the patch on the IBM Support website.
What is the severity of CVE-2021-29903?
CVE-2021-29903 has a severity rating of 9.8 (Critical).