First published: Tue Jan 28 2025(Updated: )
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM B2B Sterling Integrator | >=6.0.0.0<=6.1.2.5>=6.2.0.0<=6.2.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-50316 has been rated as a high severity vulnerability due to its potential for remote exploitation and impact on sensitive data.
To mitigate CVE-2023-50316, users should upgrade to IBM Sterling B2B Integrator version 6.2.0.2 or later, which includes fixes for the SQL injection vulnerability.
CVE-2023-50316 affects IBM Sterling B2B Integrator versions 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1.
Exploitation of CVE-2023-50316 could allow attackers to view, add, modify, or delete information in the back-end database.
Currently, there are no documented workarounds for CVE-2023-50316, and users are advised to upgrade to a patched version.