CVE-2019-4728

Description

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code with SYSTEM privileges. IBM X-Force ID: 172452.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
16.34

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-4728,CVE-2020-4761,CVE-2020-4762 are affected in IBM Sterling B2B Integrator 5.2.6.5_2Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.2Windows
Vulnerabilities CVE-2019-4728,CVE-2020-4761,CVE-2020-4762 are affected in IBM Sterling B2B Integrator 6.1.0.0Windows
Vulnerabilities CVE-2019-4728,CVE-2020-4329,CVE-2020-4761,CVE-2020-4762 are affected in IBM Sterling B2B Integrator 6.1.0.0Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234