HIGH
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection
Published Nov 16, 2020
8.8
HIGHCVSS 3.1
EPSS 1.31%
Description
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 186091.
Affected products
-
- Version 5.2.0.0StatusaffectedConstraints-
- Version 5.2.6.5StatusaffectedConstraints-
- Version 6.0.0.0StatusaffectedConstraints-
- Version 6.0.3.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| IBM | Sterling B2B Integrator | n/a |
|
OR
- ≥ 5.2.0.0 · ≤ 5.2.6.5
- ≥ 6.0.0.0 · ≤ 6.0.3.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-25902 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/186091 vdb-entryx_refsource_XFVDB EntryVendor Advisory
- https://www.ibm.com/support/pages/node/6367995 x_refsource_CONFIRMPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-25902 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/186091 | vdb-entryx_refsource_XFVDB EntryVendor Advisory | |
| https://www.ibm.com/support/pages/node/6367995 | x_refsource_CONFIRMPatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Nov 16, 2020
Updated Sep 16, 2024
Reserved Dec 30, 2019
Link CVE-2020-4655
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-25902 Assigner ibm
Published Nov 16, 2020
Updated Sep 16, 2024
Exploited since n/a
Link EUVD-2020-25902