Impact
The vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway can allow a remote authenticated attacker to bypass security restrictions because of improper authentication handling in the Dashboard. This flaw is classified as an authentication bypass (CWE‑287).
Affected Systems
Affected products are IBM Sterling B2B Integrator and IBM Sterling File Gateway in Standard Edition. Versions vulnerable include 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 through 6.2.1.2, 6.2.2.0 through 6.2.2.1. The issue applies to both regular and container deployments, with updated container images available in IBM Entitled Registry.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score of < 1% indicates an extremely low exploitation probability, suggesting no current widespread exploitation data. The vulnerability is not listed in the CISA KEV catalog. Attackers must possess valid credentials to exploit the flaw; once authenticated, they can bypass security restrictions.
OpenCVE Enrichment