IBM Sterling B2B Integrator and Sterling File Gateway CVE-2013-0476 Command Injection Vulnerability
BID:60995
Info
IBM Sterling B2B Integrator and Sterling File Gateway CVE-2013-0476 Command Injection Vulnerability
| Bugtraq ID: | 60995 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-0476 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2013 12:00AM |
| Updated: | Jul 05 2013 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
IBM Sterling B2B Integrator and Sterling File Gateway CVE-2013-0476 Command Injection Vulnerability
IBM Sterling B2B Integrator and Sterling File Gateway are prone to a command-injection vulnerability.
Exploiting this issue could allow an attacker to execute arbitrary FTP commands in the context of the affected application.
IBM Sterling B2B Integrator and Sterling File Gateway are prone to a command-injection vulnerability.
Exploiting this issue could allow an attacker to execute arbitrary FTP commands in the context of the affected application.
Exploit / POC
IBM Sterling B2B Integrator and Sterling File Gateway CVE-2013-0476 Command Injection Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
IBM Sterling B2B Integrator and Sterling File Gateway CVE-2013-0476 Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM Sterling B2B Integrator and Sterling File Gateway CVE-2013-0476 Command Injection Vulnerability
References:
References:
- IBM Homepage (IBM)