CVE-2019-4728
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code with SYSTEM privileges. IBM X-Force ID: 172452.
Affected (3)
Products: Ibm: Sterling B2b Integrator
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 5.2.0.0 to 5.2.6.5_2 |
| Running on/with | Platform Versions |
|---|---|
Hp Hp Ux | All versions |
Ibm Aix | All versions |
Ibm I | All versions |
Linux Linux Kernel | All versions |
Microsoft Windows | All versions |
Oracle Solaris | All versions |
References (4)
Source: psirt@us.ibm.com
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.