Description
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 Standard Edition could allow a remote authenticated attacker to bypass security restrictions due to improper authentication.
Published: 2026-09-14
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows a remotely authenticated attacker to bypass security restrictions by exploiting improper authentication handling in the Dashboard of IBM Sterling B2B Integrator and IBM Sterling File Gateway. This flaw is classified as an authentication bypass (CWE‑287), enabling the attacker to gain elevated access privileges beyond what was originally granted.

Affected Systems

Affected products are IBM Sterling B2B Integrator and IBM Sterling File Gateway in Standard Edition. Versions vulnerable include 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 through 6.2.1.2, and 6.2.2.0 through 6.2.2.1. The issue applies to both regular and container deployments, with updated container images available in IBM Entitled Registry.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity, and the EPSS score is not available, suggesting no current widespread exploitation data. The vulnerability is not listed in the CISA KEV catalog. Attackers must possess valid credentials to exploit the flaw, but once authenticated they can bypass other security controls and potentially access sensitive data or configuration information.

Generated by OpenCVE AI on September 15, 2026 at 09:52 UTC.

Remediation

Vendor Solution

ProductVersionAPARRemediation & FixIBM Sterling B2B Integrator6.2.0.0 - 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1IT49630Apply 6.2.1.2_1 or 6.2.2.1_1IBM Sterling File Gateway6.2.0.0 - 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1IT49630Apply 6.2.1.2_1 or 6.2.2.1_1 The IIM versions 6.2.1.2_1 and 6.2.2.1_1 are available on Fix Central http://www-933.ibm.com/support/fixcentral/swg/selectFixes .  The container versions of 6.2.1.2_1 and 6.2.2.1_1 are available in IBM Entitled Registry * cp.icr.io/cp/ibm-b2bi for IBM Sterling B2B Integrator * cp.icr.io/cp/ibm-sfg for IBM Sterling File Gateway


OpenCVE Recommended Actions

  • Upgrade IBM Sterling B2B Integrator to version 6.2.1.2_1 or later, or 6.2.2.1_1 or later; similarly update IBM Sterling File Gateway to 6.2.1.2_1 or 6.2.2.1_1 or later.
  • If using container deployments, replace the existing images with the updated ones from the IBM Entitled Registry (cp.icr.io/cp/ibm-b2bi for Sterling B2B Integrator and cp.icr.io/cp/ibm-sfg for Sterling File Gateway).
  • If immediate upgrade is not possible, restrict external network access to the Dashboard and enforce stricter role‑based access controls to prevent unauthorized users from accessing restricted areas.

Generated by OpenCVE AI on September 15, 2026 at 09:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 Standard Edition could allow a remote authenticated attacker to bypass security restrictions due to improper authentication.
Title The Dashboard of IBM Sterling B2B Integrator and IBM Sterling File Gateway are Vulnerable to Improper Access Control
First Time appeared Ibm
Ibm sterling B2b Integrator
Ibm sterling File Gateway
Weaknesses CWE-287
CPEs cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.0.6_2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.0.6_2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm sterling B2b Integrator
Ibm sterling File Gateway
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Ibm Sterling B2b Integrator Sterling File Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-14T21:04:21.572Z

Reserved: 2026-08-07T14:26:03.854Z

Link: CVE-2026-19273

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T21:17:04.490

Modified: 2026-09-14T21:17:04.490

Link: CVE-2026-19273

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T10:00:16Z

Weaknesses