Junglewise Threat Intelligence

CVE-2026-7362: IBM Sterling B2B Integrator and File Gateway improper access control

CVE-2026-7362 · Severity: medium · CVSS 4.3 · Published 2026-07-28

Technologies: IBM Sterling File Gateway, IBM Sterling B2b Integrator. Vendors: IBM.

Executive brief

IBM Sterling B2B Integrator and Sterling File Gateway are platforms used by organizations to manage complex data exchanges and file transfers with business partners. A security vulnerability in these systems could allow a standard user to access sensitive information that is normally restricted to administrators. This could lead to the unauthorized disclosure of internal configuration details or business data, though it requires the attacker to already have a valid user account.

Technical details

An improper access control vulnerability (CWE-284) exists in IBM Sterling B2B Integrator and IBM Sterling File Gateway. The flaw allows a remote authenticated attacker with low privileges to bypass intended access restrictions and view sensitive information that should be restricted to administrative or privileged users. The vulnerability is reachable via the network and does not require user interaction. IBM has released patches to address this issue in versions 6.2.1.2 and 6.2.2.1.

Affected products

  • IBM Sterling B2B Integrator 6.2.1.0 - 6.2.1.1_2, 6.2.2.0 - 6.2.2.0_1
  • IBM Sterling File Gateway 6.2.1.0 - 6.2.1.1_2, 6.2.2.0 - 6.2.2.0_1

Timeline

  • 2026-07-22: disclosed: Initial publication by IBM
  • 2026-07-22: patched: Fixes released in versions 6.2.1.2 and 6.2.2.1
  • 2026-07-28: advisory: NVD publication date

References

Related threats