Executive brief
IBM Sterling B2B Integrator and File Gateway are enterprise integration platforms used to manage secure data exchanges and file transfers between business partners. A remote authenticated attacker can bypass security restrictions in the Dashboard component due to improper authentication controls, allowing unauthorized access to sensitive functionality. This vulnerability requires valid login credentials but could enable attackers with legitimate access to escalate privileges or access data they should not be able to reach.
Technical details
This vulnerability is classified as improper authentication (CWE-287) affecting the Dashboard component of both IBM Sterling B2B Integrator and File Gateway versions 6.2.0.0 through 6.2.2.1. The root cause is inadequate authentication validation that allows authenticated users to bypass security restrictions. The attack vector is network-based and requires prior authentication; no user interaction is necessary once an attacker has valid credentials. An authenticated attacker can circumvent access controls to perform unauthorized operations. IBM has released patches (6.2.1.2_1 and 6.2.2.1_1) available through Fix Central and container registries to remediate this issue.
Affected products
- IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 through 6.2.1.2, 6.2.2.0 through 6.2.2.1
- IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 through 6.2.1.2, 6.2.2.0 through 6.2.2.1
Timeline
- 2026-09-14: disclosed: Security bulletin published
- 2026-09-14: patched: Fixes 6.2.1.2_1 and 6.2.2.1_1 available on Fix Central