IBM Sterling File Gateway has addressed the information disclosure vulnerability
CVEID: CVE-2019-4147 DESCRIPTION: IBM Sterling File Gateway is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVSS Base Score: 4.7
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/158413> for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L)
IBM Sterling File Gateway 2.2.0.0 - 6.0.1.0
PRODUCT & Version
| APAR |
Remediation/Fix
—|—|—
IBM Sterling File Gateway 2.2.0.0 - 6.0.1.0
| IT28281 |
Apply IBM Sterling B2B Integrator version 5.2.6.4_2 or 6.0.2.0 on Fix Central
None