Description
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to an information disclosure due to sensitive information being included in the source code comments of a dashboard component.
Published: 2026-07-28
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An information‑disclosure vulnerability exists in IBM Sterling B2B Integrator and IBM Sterling File Gateway releases 6.2.0.0 through 6.2.2.0_1. The flaw arises because sensitive data is inadvertently included in source‑code comments of a dashboard component. An attacker able to view those comments could obtain confidential configuration or credential information, potentially compromising system confidentiality. The weakness is catalogued as CWE‑615 and does not provide an execution path or privilege escalation; it is limited to disclosure of data already present in the code base.

Affected Systems

Affected products are IBM Sterling B2B Integrator and IBM Sterling File Gateway. Vulnerable versions include 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 for both products. The PSI patches are available in Fix Central and the IBM Entitled Registry.

Risk and Exploitability

The CVSS score of 4.3 and an EPSS score of less than 1% indicate moderate severity with a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would likely require access to the source code for the dashboard component, either through a developer environment or via a compromised workstation. No privileged elevation or remote execution is possible; the attack vector is inferred to be local or developer‑level access rather than external network exploitation.

Generated by OpenCVE AI on August 3, 2026 at 14:27 UTC.

Remediation

Vendor Solution

ProductVersionAPARRemediation & FixIBM Sterling B2B Integrator and IBM Sterling File Gateway6.2.0.0 - 6.2.0.5_2 IT49080     Apply B2Bi 6.2.0.6, 6.2.1.2, 6.2.2.1IBM Sterling B2B Integrator and IBM Sterling File Gateway6.2.1.0 - 6.2.1.1_2 IT49080     Apply B2Bi 6.2.1.2, 6.2.2.1IBM Sterling B2B Integrator and IBM Sterling File Gateway6.2.2.0 - 6.2.2.0_1   IT49080    Apply B2Bi 6.2.2.1 The IIM versions of 6.2.0.6, 6.2.1.2 and 6.2.2.1 are available on  Fix Central http://www-933.ibm.com/support/fixcentral/swg/selectFixes .  The container version of 6.2.0.6, 6.2.1.2 and 6.2.2.1 are available in IBM Entitled Registry.


OpenCVE Recommended Actions

  • Upgrade IBM Sterling B2B Integrator or File Gateway to a patched release: apply B2Bi 6.2.0.6, 6.2.1.2, or 6.2.2.1 depending on your current version.
  • Download the appropriate fix from Fix Central or the IBM Entitled Registry and apply the APAR IT49080.
  • As a temporary measure, remove or redact the sensitive information from source‑code comments if the patch cannot be applied immediately.

Generated by OpenCVE AI on August 3, 2026 at 14:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to an information disclosure due to sensitive information being included in the source code comments of a dashboard component.
Title Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway due to information disclosure
First Time appeared Ibm
Ibm sterling B2b Integrator
Ibm sterling File Gateway
Weaknesses CWE-615
CPEs cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.0.5_2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.1.1_2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.2.0_1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.0.5_2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.1.1_2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.2.0_1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm sterling B2b Integrator
Ibm sterling File Gateway
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Ibm Sterling B2b Integrator Sterling File Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-29T13:55:30.106Z

Reserved: 2026-02-24T20:59:24.546Z

Link: CVE-2026-3158

cve-icon Vulnrichment

Updated: 2026-07-29T13:55:27.078Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-28T20:17:24.823

Modified: 2026-08-03T14:27:47.300

Link: CVE-2026-3158

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:30:18Z

Weaknesses
  • CWE-615

    Inclusion of Sensitive Information in Source Code Comments