Impact
IBM Sterling B2B Integrator and IBM Sterling File Gateway versions 6.2.1.0 through 6.2.1.1_2 and 6.2.2.0 through 6.2.2.0_1 contain an improper access control flaw that permits an authenticated user to retrieve sensitive information that should be limited to privileged users. The vulnerability originates from a weakness in access control enforcement (CWE‑284), enabling data disclosure without code execution or denial of service.
Affected Systems
The affected products are IBM Sterling B2B Integrator and IBM Sterling File Gateway across the listed version ranges; users running any of these versions should verify their deployments to determine if they are impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates a low to moderate risk, and the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to be authenticated and can use the flaw to elevate their access privileges to read data normally reserved for higher‑level users; the exploit vector is likely internal and requires valid credentials.
OpenCVE Enrichment