Executive brief
IBM Sterling B2B Integrator and Sterling File Gateway are platforms used by organizations to manage complex B2B processes and secure file transfers. A security vulnerability has been identified that allows an unauthorized person to bypass security checks and view sensitive information. This could lead to the exposure of confidential business data or internal system details without requiring a valid login.
Technical details
An authorization bypass vulnerability (CWE-639) exists in IBM Sterling B2B Integrator and IBM Sterling File Gateway. The flaw is rooted in improper access control where the application relies on user-controlled keys or specially crafted HTTP requests to validate identity. A remote, unauthenticated attacker can exploit this by sending a tailored HTTP request to the server, bypassing authentication mechanisms to gain unauthorized access to sensitive data. The vulnerability affects versions 6.2.0.0 through 6.2.2.0_1 and has been addressed in patches 6.2.0.6, 6.2.1.2, and 6.2.2.1.
Affected products
- IBM Sterling B2B Integrator 6.2.0.0 - 6.2.0.5_2, 6.2.1.0 - 6.2.1.1_2, 6.2.2.0 - 6.2.2.0_1
- IBM Sterling File Gateway 6.2.0.0 - 6.2.0.5_2, 6.2.1.0 - 6.2.1.1_2, 6.2.2.0 - 6.2.2.0_1
Timeline
- 2026-07-21: advisory: Initial publication by IBM
- 2026-07-22: disclosed: NVD publication date