Junglewise Threat Intelligence

CVE-2026-3158: IBM Sterling B2B Integrator information disclosure in dashboard component

CVE-2026-3158 · Severity: medium · CVSS 4.3 · Published 2026-07-28

Executive brief

IBM Sterling B2B Integrator and Sterling File Gateway, which are used by organizations to manage secure file transfers and business-to-business transactions, are affected by a security flaw. Sensitive information was inadvertently included in the source code comments of a dashboard component. An authenticated user could view this information, potentially gaining insights into the system's internal configuration or security posture.

Technical details

This vulnerability is classified as an information disclosure (CWE-615) within the dashboard component of IBM Sterling B2B Integrator and Sterling File Gateway. The root cause is the inclusion of sensitive data within source code comments that are accessible to users. An attacker with low-privileged network access can view these comments to extract sensitive information. The vulnerability affects versions 6.2.0.0 through 6.2.2.0_1. IBM has released patches in versions 6.2.0.6, 6.2.1.2, and 6.2.2.1 to remediate this issue.

Affected products

  • IBM Sterling B2B Integrator 6.2.0.0 - 6.2.0.5_2, 6.2.1.0 - 6.2.1.1_2, 6.2.2.0 - 6.2.2.0_1
  • IBM Sterling File Gateway 6.2.0.0 - 6.2.0.5_2, 6.2.1.0 - 6.2.1.1_2, 6.2.2.0 - 6.2.2.0_1

Timeline

  • 2026-07-21: advisory: Initial publication by IBM
  • 2026-07-28: disclosed: NVD publication date
  • 2026-07-21: patched: Fixes available in versions 6.2.0.6, 6.2.1.2, and 6.2.2.1

References

Related threats