Junglewise Threat Intelligence

CVE-2026-3157: IBM Sterling B2B Integrator information disclosure in mailbox component

CVE-2026-3157 · Severity: medium · CVSS 4.3 · Published 2026-07-28

Executive brief

IBM Sterling B2B Integrator and Sterling File Gateway, which are used by organizations to securely manage large-scale file transfers and business process integration, are affected by an information disclosure vulnerability. Sensitive information was inadvertently included in the source code comments of the mailbox user interface component. An authenticated user could view this information, potentially gaining insights into the system's configuration or internal workings that could be used to facilitate further unauthorized activities.

Technical details

This vulnerability (CWE-615) exists in the mailbox component user interface of IBM Sterling B2B Integrator and Sterling File Gateway. The root cause is the inclusion of sensitive information within source code comments that are accessible to users. An authenticated attacker with network access to the mailbox UI can view these comments by inspecting the page source or client-side code. This could lead to the disclosure of internal system details or configuration data. The issue is resolved in versions 6.2.0.6, 6.2.1.2, and 6.2.2.1.

Affected products

  • IBM Sterling B2B Integrator 6.2.0.0 - 6.2.0.5_2, 6.2.1.0 - 6.2.1.1_2, 6.2.2.0 - 6.2.2.0_1
  • IBM Sterling File Gateway 6.2.0.0 - 6.2.0.5_2, 6.2.1.0 - 6.2.1.1_2, 6.2.2.0 - 6.2.2.0_1

Timeline

  • 2026-07-21: advisory: Initial publication by IBM
  • 2026-07-28: disclosed: NVD publication date

References

Related threats