Executive brief
IBM Sterling File Gateway is a secure file transfer and B2B integration platform used by enterprises to exchange sensitive business documents. A flaw in access control allows remote attackers without authentication to obtain sensitive information from the system, potentially exposing confidential business data and customer information.
Technical details
The vulnerability is an improper access control issue (CWE-284) in IBM Sterling File Gateway versions 6.2.0.0 through 6.2.2.1. It allows remote attackers to access sensitive information without proper authentication or authorization. The attack vector is network-based with no authentication required and no user interaction needed. Patches are available: versions 6.2.0.6_2, 6.2.1.2_1, and 6.2.2.1_1 address this issue.
Affected products
- IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 through 6.2.1.2, 6.2.2.0 through 6.2.2.1
Timeline
- 2026-09-14: disclosed
- 2026-09-11: advisory