First published: Tue Dec 27 2022(Updated: )
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 219510.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling B2B Integrator | >=6.0.0.0<6.0.3.7 | |
IBM Sterling B2B Integrator | >=6.1.0.0<6.1.0.6 | |
IBM Sterling B2B Integrator | >=6.1.1.0<6.1.1.2 | |
IBM Sterling B2B Integrator | =6.1.2.0 | |
<=6.0.0.0 - 6.0.3.6 | ||
<=6.1.0.0 - 6.1.0.5, 6..1.1.0 - 6.1.1.1, 6.1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-22338.
CVE-2022-22338 has a severity rating of 9.8 (Critical).
IBM Sterling B2B Integrator Standard Edition versions 6.0.0.0 through 6.1.2.1 are affected by CVE-2022-22338.
A remote attacker can exploit CVE-2022-22338 by sending specially crafted SQL statements to the vulnerable application.
Yes, IBM has provided a fix for CVE-2022-22338. Please refer to the IBM support page for more information.