CVE-2021-39085: SQL Injection
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 215888.
Other sources
IBM Sterling B2B Integrator Standard Edition is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this security vulnerability?
The vulnerability ID is CVE-2021-39085.
What is the severity of CVE-2021-39085?
The severity of CVE-2021-39085 is critical with a score of 9.8.
Which IBM product is affected by CVE-2021-39085?
IBM Sterling B2B Integrator Standard Edition is affected by CVE-2021-39085.
How can a remote attacker exploit CVE-2021-39085?
A remote attacker can exploit CVE-2021-39085 by sending specially crafted SQL statements.
Is there a patch available for CVE-2021-39085?
Yes, IBM has released a patch for CVE-2021-39085. You can find it at the following URL: [Patch URL](http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~Other%2Bsoftware&product=ibm/Other+software/Sterling+B2B+Integrator&release=All&platform=All&function=all).