VDB
CVE-2024-31903
CVE-2024-31903
PUBLISHED
CVSS 9.300000190734863 CRITICAL
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 allow an attacker on the local network to execute arbitrary code on the system, caused by the deserialization of untrusted data.
EPSS 0.97% · 58.5th percentile
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.97%
58.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ibm | sterling_b2b_integrator | 6.2.0.0, 6.0.0.0, 6.0.0.0 |
| IBM | Sterling B2B Integrator Standard Edition | 6.0.0.0, 6.2.0.0 |
Timeline
- Oct 11, 2024 CVE Published
- Jan 22, 2025 PoC Published
- Jan 22, 2025 PoC Published
- Jan 22, 2025 PoC Published
- Jan 22, 2025 PoC Published
- Jan 23, 2025 EPSS Score
- Feb 2, 2025 Coalition ESS Score
- Feb 23, 2025 EPSS Score
- Mar 13, 2025 Coalition ESS Score
- Mar 17, 2025 EPSS Score
- Mar 19, 2025 EPSS Score
- Mar 21, 2025 EPSS Score