Executive brief
IBM Sterling B2B Integrator and Sterling File Gateway are platforms used by organizations to manage secure data transfers and business process automation. A security flaw in the Ebics server component allows an authorized user to inject malicious scripts into the web interface. If another user views the affected page, an attacker could potentially steal login credentials or hijack their active session, compromising sensitive business data.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the Ebics server component of IBM Sterling B2B Integrator and Sterling File Gateway. The flaw is caused by improper neutralization of user-supplied input during web page generation (CWE-79). An authenticated attacker with low privileges can inject malicious JavaScript into the Web UI. When a victim interacts with the compromised interface, the script executes in their browser context, potentially leading to credential disclosure or session hijacking. IBM has released patches in versions 6.1.2.8, 6.2.0.6, 6.2.1.2, and 6.2.2.1 to address this issue.
Affected products
- IBM Sterling B2B Integrator 6.1.2.0 - 6.1.2.7_2, 6.2.0.0 - 6.2.0.5_2, 6.2.1.0 - 6.2.1.1_2, 6.2.2.0 - 6.2.2.0_1
- IBM Sterling File Gateway 6.1.2.0 - 6.1.2.7_2, 6.2.0.0 - 6.2.0.5_2, 6.2.1.0 - 6.2.1.1_2, 6.2.2.0 - 6.2.2.0_1
Timeline
- 2026-07-21: advisory: Initial publication by IBM
- 2026-07-30: disclosed: NVD publication date