Description
IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 could allow an authenticated user to obtain sensitive information that should only be available to a privileged user.
Published: 2026-07-28
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Sterling B2B Integrator and IBM Sterling File Gateway versions 6.2.1.0 through 6.2.1.1_2 and 6.2.2.0 through 6.2.2.0_1 contain an improper access control flaw that permits an authenticated user to retrieve sensitive information that should be limited to privileged users. The vulnerability originates from a weakness in access control enforcement (CWE‑284), enabling data disclosure without code execution or denial of service.

Affected Systems

The affected products are IBM Sterling B2B Integrator and IBM Sterling File Gateway across the listed version ranges; users running any of these versions should verify their deployments to determine if they are impacted.

Risk and Exploitability

The CVSS score of 4.3 indicates a low to moderate risk, and the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to be authenticated and can use the flaw to elevate their access privileges to read data normally reserved for higher‑level users; the exploit vector is likely internal and requires valid credentials.

Generated by OpenCVE AI on August 3, 2026 at 14:35 UTC.

Remediation

Vendor Solution

ProductVersionAPARRemediation & FixIBM Sterling B2B Integrator and IBM Sterling File Gateway6.2.1.0 - 6.2.1.1_2 IT49322     Apply B2Bi 6.2.1.2, 6.2.2.1IBM Sterling B2B Integrator and IBM Sterling File Gateway6.2.2.0 - 6.2.2.0_1   IT49322     Apply B2Bi 6.2.2.1 The IIM versions of 6.2.1.2 and 6.2.2.1 are available on Fix Central http://www-933.ibm.com/support/fixcentral/swg/selectFixes .  The container version of 6.2.1.2 and 6.2.2.1 are available in IBM Entitled Registry.


OpenCVE Recommended Actions

  • Install IBM Sterling B2B Integrator or File Gateway version 6.2.1.2 or 6.2.2.1 from IBM Fix Central or the IBM Entitled Registry
  • Deploy the patched version across all production environments, including container images
  • If a patch cannot be applied immediately, mitigate by applying network or application‑level access controls to restrict the ability of authenticated users to access privileged data, following the vendor guidance for role‑based access restrictions

Generated by OpenCVE AI on August 3, 2026 at 14:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 could allow an authenticated user to obtain sensitive information that should only be available to a privileged user.
Title Improper Access Control Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway
First Time appeared Ibm
Ibm sterling B2b Integrator
Ibm sterling File Gateway
Weaknesses CWE-284
CPEs cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.1.1_2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.2.0_1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.1.1_2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.2.0_1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm sterling B2b Integrator
Ibm sterling File Gateway
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Ibm Sterling B2b Integrator Sterling File Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-29T13:58:19.335Z

Reserved: 2026-04-28T20:09:35.647Z

Link: CVE-2026-7362

cve-icon Vulnrichment

Updated: 2026-07-29T13:58:16.074Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-28T19:17:41.587

Modified: 2026-08-03T15:17:50.003

Link: CVE-2026-7362

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:45:04Z

Weaknesses