Description
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Published: 2026-07-28
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a classic SQL injection flaw that allows a remote attacker to send specially constructed SQL statements to the affected IBM Sterling B2B Integrator or IBM Sterling File Gateway instances. By exploiting this weakness, an attacker could view, add, modify, or delete records in the back‑end database, compromising the confidentiality, integrity, or availability of the data the application manages. The weakness is coded as CWE‑89. The impact is limited to the scope of the authenticated application context, but the potential to alter or expose mission critical business data makes it a high‑risk finding.

Affected Systems

IBM Sterling B2B Integrator versions 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1, as well as IBM Sterling File Gateway versions 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1.

Risk and Exploitability

The CVSS score of 8.1 classifies this flaw as high severity, though the EPSS score is below 1 percent, indicating a low predicted exploitation probability at this time. The vulnerability is not listed in the CISA KEV catalog. An attacker would need remote access to the application interface where the injection point exists, but no additional prerequisites are disclosed. Once reached, the flaw can be exploited without additional privilege escalation.

Generated by OpenCVE AI on August 3, 2026 at 14:37 UTC.

Remediation

Vendor Solution

ProductVersionAPARRemediation & FixIBM Sterling B2B Integrator and IBM Sterling File Gateway6.2.0.0 - 6.2.0.5_2 IT48302     Apply B2Bi 6.2.0.6, 6.2.1.2, 6.2.2.1IBM Sterling B2B Integrator and IBM Sterling File Gateway6.2.1.0 - 6.2.1.1_2 IT48302     Apply B2Bi 6.2.1.2, 6.2.2.1IBM Sterling B2B Integrator and IBM Sterling File Gateway6.2.2.0 - 6.2.2.0_1   IT48302    Apply B2Bi 6.2.2.1 The IIM versions of 6.2.0.6, 6.2.1.2 and 6.2.2.1 are available on  Fix Central http://www-933.ibm.com/support/fixcentral/swg/selectFixes .  The container version of 6.2.0.6, 6.2.1.2 and 6.2.2.1 are available in IBM Entitled Registry.


OpenCVE Recommended Actions

  • Apply the IBM-released patches for B2Bi versions 6.2.0.6, 6.2.1.2, or 6.2.2.1, which address the SQL injection issue for both Sterling B2B Integrator and Sterling File Gateway. The patches are available through Fix Central for IIM deployments and the IBM Entitled Registry for container deployments.
  • If upgrading is not immediately possible, isolate the vulnerable components behind a firewall or network segment that restricts external access to the interfaces that accept user input.
  • Configure the application with least‑privilege database credentials and enable audit logging to detect anomalous query patterns that might indicate an attempted injection attack.

Generated by OpenCVE AI on August 3, 2026 at 14:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Title SQL injection Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway
First Time appeared Ibm
Ibm sterling B2b Integrator
Ibm sterling File Gateway
Weaknesses CWE-89
CPEs cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.0.5_2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.1.1_2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.2.0_1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.0.5_2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.1.1_2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.2.0_1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm sterling B2b Integrator
Ibm sterling File Gateway
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Ibm Sterling B2b Integrator Sterling File Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-29T03:56:08.092Z

Reserved: 2026-05-04T13:28:13.107Z

Link: CVE-2026-7769

cve-icon Vulnrichment

Updated: 2026-07-28T18:41:46.731Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-28T19:17:41.720

Modified: 2026-08-03T15:05:36.667

Link: CVE-2026-7769

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:45:04Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')