Impact
IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection (CWE‑89). A privileged user can send specially crafted SQL statements to the back‑end database, allowing the attacker to view, add, modify, or delete information stored in the database. This unauthorized access results in read or write privileges that compromise data confidentiality and integrity.
Affected Systems
IBM Sterling B2B Integrator and IBM Sterling File Gateway are affected by this vulnerability. Versions 6.2.1.0 through 6.2.1.1_2 and 6.2.2.0 through 6.2.2.0_1 contain the flaw. IBM recommends upgrading to the patched releases – 6.2.1.2 for the 6.2.1 line and 6.2.2.1 for the 6.2.2 line – which are available via Fix Central and the IBM Entitled Registry.
Risk and Exploitability
The CVSS base score of 6 indicates a moderate severity for this SQL injection. The EPSS score of less than 1% reflects a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to possess privileged credentials that can access the vulnerable interfaces, implying an existing or compromised account. Once authenticated, the attacker can compromise the database, leading to loss of data confidentiality and integrity. For environments where privileged access is broad or poorly monitored, the risk may rise to medium‑high; however, in tightly controlled setups the risk remains moderate.
OpenCVE Enrichment