Description
IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Published: 2026-06-22
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection (CWE‑89). A privileged user can send specially crafted SQL statements to the back‑end database, allowing the attacker to view, add, modify, or delete information stored in the database. This unauthorized access results in read or write privileges that compromise data confidentiality and integrity.

Affected Systems

IBM Sterling B2B Integrator and IBM Sterling File Gateway are affected by this vulnerability. Versions 6.2.1.0 through 6.2.1.1_2 and 6.2.2.0 through 6.2.2.0_1 contain the flaw. IBM recommends upgrading to the patched releases – 6.2.1.2 for the 6.2.1 line and 6.2.2.1 for the 6.2.2 line – which are available via Fix Central and the IBM Entitled Registry.

Risk and Exploitability

The CVSS base score of 6 indicates a moderate severity for this SQL injection. The EPSS score of less than 1% reflects a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to possess privileged credentials that can access the vulnerable interfaces, implying an existing or compromised account. Once authenticated, the attacker can compromise the database, leading to loss of data confidentiality and integrity. For environments where privileged access is broad or poorly monitored, the risk may rise to medium‑high; however, in tightly controlled setups the risk remains moderate.

Generated by OpenCVE AI on July 29, 2026 at 23:36 UTC.

Remediation

Vendor Solution

Product Version APAR Remediation & Fix IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.1.0 - 6.2.1.1_2  IT49319     Apply B2Bi 6.2.1.2, 6.2.2.1 IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.2.0 - 6.2.2.0_1    IT49319     Apply B2Bi 6.2.2.1  The IIM versions of 6.2.1.2 and 6.2.2.1 are available on Fix Central http://www-933.ibm.com/support/fixcentral/swg/selectFixes .  The container version of 6.2.1.2 and 6.2.2.1 are available in IBM Entitled Registry.


OpenCVE Recommended Actions

  • Update IBM Sterling B2B Integrator to version 6.2.1.2 or IBM Sterling File Gateway to version 6.2.2.1 using the fixes available from IBM Fix Central or the IBM Entitled Registry.
  • Restrict access to the components that process user‑supplied input, ensuring that only authenticated and authorized accounts with the minimum necessary privileges can invoke the vulnerable functionality.
  • Implement application‑level input validation or rely on parameterized queries to mitigate potential injection attacks, and review database user permissions to provide only read‑only access where possible.

Generated by OpenCVE AI on July 29, 2026 at 23:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 14:15:00 +0000


Wed, 22 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Description IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.1.0 - 6.2.1.1_2 and 6.2.2.0 - 6.2.2.0_1 are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Title IBM Sterling File Gateway server-side request forgery (SSRF) IBM Sterling File Gateway SQL Injection
Weaknesses CWE-918 CWE-89
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L'}


Wed, 22 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Description IBM Watson Speech Services Cartridge is vulnerable to Server-Side Request Forgery (SSRF) in Sterling File Gateway, due to a flaw which may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks [GHSA-rr7j-v2q5-chgv] [CVE-2026-7253]. IBM Sterling File Gateway is used in our speech runtimes. This vulnerabilitiy has been addressed. Please read the details for remediation below. IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.1.0 - 6.2.1.1_2 and 6.2.2.0 - 6.2.2.0_1 are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Title IBM Watson Speech Services Cartridge is vulnerable to Server-Side Request Forgery (SSRF) in Sterling File Gateway IBM Sterling File Gateway server-side request forgery (SSRF)
First Time appeared Ibm sterling B2b Integrator
Ibm sterling File Gateway
CPEs cpe:2.3:a:ibm:ibm_watson_speech_services_cartridge:*:*:*:*:*:*:*:* cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:*:*:*:*:*:*:*:*
Vendors & Products Ibm sterling B2b Integrator
Ibm sterling File Gateway

Tue, 23 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 22 Jun 2026 15:45:00 +0000

Type Values Removed Values Added
Description IBM Watson Speech Services Cartridge is vulnerable to Server-Side Request Forgery (SSRF) in Sterling File Gateway, due to a flaw which may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks [GHSA-rr7j-v2q5-chgv] [CVE-2026-7253]. IBM Sterling File Gateway is used in our speech runtimes. This vulnerabilitiy has been addressed. Please read the details for remediation below.
Title IBM Watson Speech Services Cartridge is vulnerable to Server-Side Request Forgery (SSRF) in Sterling File Gateway
First Time appeared Ibm
Ibm ibm Watson Speech Services Cartridge
Weaknesses CWE-918
CPEs cpe:2.3:a:ibm:ibm_watson_speech_services_cartridge:*:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm ibm Watson Speech Services Cartridge
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Ibm Watson Speech Services Cartridge Sterling B2b Integrator Sterling File Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-23T13:51:40.526Z

Reserved: 2026-04-27T22:02:11.814Z

Link: CVE-2026-7253

cve-icon Vulnrichment

Updated: 2026-06-23T13:43:14.220Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T23:45:03Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')