Executive brief
IBM Sterling File Gateway is a secure file transfer solution used by enterprises to exchange documents with trading partners and internal systems. A remote attacker can bypass authentication entirely by exploiting an unvalidated single sign-on (SSO) header, gaining full access to the system without valid credentials. This could allow an attacker to steal, modify, or delete sensitive business documents and data in transit. The vulnerability requires no special privileges or user interaction to exploit.
Technical details
IBM Sterling File Gateway improperly validates SSO headers during authentication, allowing remote attackers to forge authenticated sessions without providing valid credentials. The vulnerability is a CWE-287 improper authentication issue exploitable over the network with no prerequisites. An unauthenticated attacker gains full access to all gateway functionality and protected data.
Affected products
- IBM Sterling File Gateway 6.2.0.0 through 6.2.2.1
Timeline
- 2026-09-15: disclosed: IBM security bulletin published
- 2026-09-15: patched: Patches available: 6.2.0.6_2, 6.2.1.2_1, 6.2.2.1_1