CVE-2022-22338: IBM Sterling B2B Integrator Standard Edition SQL injection
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 219510.
Other sources
IBM Sterling B2B Integrator Standard Edition is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-22338.
What is the severity rating of CVE-2022-22338?
CVE-2022-22338 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2022-22338?
IBM Sterling B2B Integrator Standard Edition versions 6.0.0.0 through 6.1.2.1 are affected by CVE-2022-22338.
How can a remote attacker exploit CVE-2022-22338?
A remote attacker can exploit CVE-2022-22338 by sending specially crafted SQL statements to the vulnerable application.
Is there a fix available for CVE-2022-22338?
Yes, IBM has provided a fix for CVE-2022-22338. Please refer to the IBM support page for more information.