IT

Tracker / CVE-2019-4728

CVE-2019-4728

High 8.8

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code with SYSTEM privileges. IBM X-Force ID: 172452.

Affected products and versions

ibm sterling_b2b_integrator
ibm sterling_b2b_integrator · 5.2.0.0 → 5.2.6.5_2
ibm sterling_b2b_integrator · 6.0.0.0 → 6.0.3.2

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References