QID 373312

Date Published: 2021-05-13

QID 373312: IBM Sterling B2B Integrator Multiple security Vulnerabilities

IBM Sterling B2B Integrator helps companies integrate all their complex B2B/EDI processes across their partner communities in a single gateway. FasterXML jackson-databind in IBM b2b integrator could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization when using the xalan JNDI gadget. By sending specially-crafted input, an attacker could exploit this vulnerability to execute arbitrary code on the system.

Affected Versions:
IBM Sterling B2B Integrator 5.2.6.2 - 6.0.3.1

QID Detection Logic:(Authenticated)
This QID checks the vulnerable version of IBM B2B installed and checks if patch is applied or not.

Successful exploitation allows a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization when using the xalan JNDI gadget. By sending specially-crafted input, an attacker could exploit this vulnerability to execute arbitrary code on the system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to apply B2B Integrator fix pack 5.2.6.5_2 or 6.0.3.2 to fix this vulnerability. More information can be found CVE-2019-14892, CVE-2019-14893.
    Vendor References

    CVEs related to QID 373312

    Software Advisories
    Advisory ID Software Component Link
    CVE-2019-14892, CVE-2019-14893 URL Logo www.ibm.com/support/pages/node/6210298