Executive brief
IBM Sterling B2B Integrator and Sterling File Gateway are platforms used by organizations to manage complex business-to-business transactions and secure file transfers. A security vulnerability has been identified that could allow an attacker to manipulate the underlying database. If exploited, this could lead to the unauthorized viewing, modification, or deletion of sensitive business data and transaction records.
Technical details
A SQL injection vulnerability (CWE-89) exists in IBM Sterling B2B Integrator and IBM Sterling File Gateway. The flaw is caused by improper neutralization of special elements used in SQL commands. A remote attacker with low privileges can exploit this by sending specially crafted SQL statements over the network. Successful exploitation allows the attacker to perform unauthorized read, write, or delete operations against the back-end database. IBM has released patches (6.2.0.6, 6.2.1.2, and 6.2.2.1) to address this issue.
Affected products
- IBM Sterling B2B Integrator 6.2.0.0 - 6.2.0.5_2, 6.2.1.0 - 6.2.1.1_2, 6.2.2.0 - 6.2.2.0_1
- IBM Sterling File Gateway 6.2.0.0 - 6.2.0.5_2, 6.2.1.0 - 6.2.1.1_2, 6.2.2.0 - 6.2.2.0_1
Timeline
- 2026-07-24: advisory: Initial IBM publication
- 2026-07-28: disclosed: NVD publication date