Impact
This vulnerability permits an unauthenticated user to send a specially crafted HTTP request that bypasses the authentication mechanism in IBM Sterling B2B Integrator and IBM Sterling File Gateway, allowing reading of sensitive information stored in the system. The weakness is an authorization bypass (CWE-639).
Affected Systems
IBM Sterling B2B Integrator and IBM Sterling File Gateway versions 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 are impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk. The EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely over HTTP/HTTPS without authentication, implying that any exposed instance could be targeted if it accepts unauthenticated connections. No publicly disclosed exploitation code is mentioned in the CVE description, but the path is clear and requires no special privileges on the target.
OpenCVE Enrichment