Executive brief
IBM Sterling B2B Integrator and Sterling File Gateway are platforms used by organizations to manage secure file transfers and business-to-business transactions. A vulnerability in these systems causes sensitive information to be recorded in plain text within system log files. If an authorized user with high-level privileges accesses these logs, they could view confidential data that should otherwise be protected, potentially leading to further unauthorized access or data exposure.
Technical details
The vulnerability is classified as CWE-532 (Insertion of Sensitive Information into Log File). It affects the logging mechanisms of IBM Sterling B2B Integrator and Sterling File Gateway, where sensitive data is inadvertently written to logs in a readable format. An attacker must have high-level administrative or system privileges (PR:H) to access these log files. While the attack vector is listed as network-based, the primary risk is the exposure of confidential information to internal users who have the authority to view system logs but should not have access to the specific sensitive data contained within them. IBM has released patches (6.2.0.6, 6.2.1.2, and 6.2.2.1) to remediate this issue.
Affected products
- IBM Sterling B2B Integrator 6.2.0.0 - 6.2.0.5_2, 6.2.1.0 - 6.2.1.1_2, 6.2.2.0 - 6.2.2.0_1
- IBM Sterling File Gateway 6.2.0.0 - 6.2.0.5_2, 6.2.1.0 - 6.2.1.1_2, 6.2.2.0 - 6.2.2.0_1
Timeline
- 2026-07-21: disclosed: Initial publication by IBM
- 2026-07-21: patched: Fixes released in versions 6.2.0.6, 6.2.1.2, and 6.2.2.1
- 2026-07-28: advisory: NVD publication date