Description
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2,  6.2.1.0 through 6.2.1.1_2, and  6.2.2.0 through 6.2.2.0_1 could allow an unauthenticated user to read sensitive information by bypassing authentication through a specially crafted HTTP request.
Published: 2026-07-22
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability permits an unauthenticated user to send a specially crafted HTTP request that bypasses the authentication mechanism in IBM Sterling B2B Integrator and IBM Sterling File Gateway, allowing reading of sensitive information stored in the system. The weakness is an authorization bypass (CWE-639).

Affected Systems

IBM Sterling B2B Integrator and IBM Sterling File Gateway versions 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 are impacted.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk. The EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely over HTTP/HTTPS without authentication, implying that any exposed instance could be targeted if it accepts unauthenticated connections. No publicly disclosed exploitation code is mentioned in the CVE description, but the path is clear and requires no special privileges on the target.

Generated by OpenCVE AI on August 3, 2026 at 23:24 UTC.

Remediation

Vendor Solution

ProductVersionAPARRemediation & FixIBM Sterling B2B Integrator and IBM Sterling File Gateway6.2.0.0 - 6.2.0.5_2 IT49168     Apply B2Bi 6.2.0.6, 6.2.1.2, 6.2.2.1IBM Sterling B2B Integrator and IBM Sterling File Gateway6.2.1.0 - 6.2.1.1_2 IT49168     Apply B2Bi 6.2.1.2, 6.2.2.1IBM Sterling B2B Integrator and IBM Sterling File Gateway6.2.2.0 - 6.2.2.0_1   IT49168    Apply B2Bi 6.2.2.1   The IIM versions of 6.2.0.6, 6.2.1.2 and 6.2.2.1 are available on  Fix Central http://www-933.ibm.com/support/fixcentral/swg/selectFixes .  The container version of 6.2.0.6, 6.2.1.2 and 6.2.2.1 are available in IBM Entitled Registry.


OpenCVE Recommended Actions

  • Apply the official IBM patch (B2Bi 6.2.0.6, 6.2.1.2, or 6.2.2.1) from Fix Central or the IBM Entitled Registry.
  • Limit inbound HTTP/HTTPS traffic to trusted hosts or apply firewall rules to restrict access to the application.
  • Disable the default authentication bypass endpoints or enforce strict API key validation if available.

Generated by OpenCVE AI on August 3, 2026 at 23:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Description IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2,  6.2.1.0 through 6.2.1.1_2, and  6.2.2.0 through 6.2.2.0_1 could allow an unauthenticated user to read sensitive information by bypassing authentication through a specially crafted HTTP request.
Title IBM Sterling B2B Integrator and IBM Sterling File Gateway Authorization Bypass
First Time appeared Ibm
Ibm sterling B2b Integrator
Ibm sterling File Gateway
Weaknesses CWE-639
CPEs cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:*:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm sterling B2b Integrator
Ibm sterling File Gateway
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Ibm Sterling B2b Integrator Sterling File Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-23T13:58:49.327Z

Reserved: 2026-03-03T14:50:55.686Z

Link: CVE-2026-3482

cve-icon Vulnrichment

Updated: 2026-07-23T13:58:43.848Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-22T19:17:03.233

Modified: 2026-07-23T14:17:12.807

Link: CVE-2026-3482

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:30:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key