Impact
The vulnerability allows a remotely authenticated attacker to bypass security restrictions by exploiting improper authentication handling in the Dashboard of IBM Sterling B2B Integrator and IBM Sterling File Gateway. This flaw is classified as an authentication bypass (CWE‑287), enabling the attacker to gain elevated access privileges beyond what was originally granted.
Affected Systems
Affected products are IBM Sterling B2B Integrator and IBM Sterling File Gateway in Standard Edition. Versions vulnerable include 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 through 6.2.1.2, and 6.2.2.0 through 6.2.2.1. The issue applies to both regular and container deployments, with updated container images available in IBM Entitled Registry.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score is not available, suggesting no current widespread exploitation data. The vulnerability is not listed in the CISA KEV catalog. Attackers must possess valid credentials to exploit the flaw, but once authenticated they can bypass other security controls and potentially access sensitive data or configuration information.
OpenCVE Enrichment