Junglewise Threat Intelligence

CVE-2026-7769: IBM Sterling B2B Integrator and Sterling File Gateway SQL injection

CVE-2026-7769 · Severity: high · CVSS 8.1 · Published 2026-07-28

Executive brief

IBM Sterling B2B Integrator and Sterling File Gateway are platforms used by organizations to manage complex business-to-business transactions and secure file transfers. A security vulnerability has been identified that could allow an attacker to manipulate the underlying database. If exploited, this could lead to the unauthorized viewing, modification, or deletion of sensitive business data and transaction records.

Technical details

A SQL injection vulnerability (CWE-89) exists in IBM Sterling B2B Integrator and IBM Sterling File Gateway. The flaw is caused by improper neutralization of special elements used in SQL commands. A remote attacker with low privileges can exploit this by sending specially crafted SQL statements over the network. Successful exploitation allows the attacker to perform unauthorized read, write, or delete operations against the back-end database. IBM has released patches (6.2.0.6, 6.2.1.2, and 6.2.2.1) to address this issue.

Affected products

  • IBM Sterling B2B Integrator 6.2.0.0 - 6.2.0.5_2, 6.2.1.0 - 6.2.1.1_2, 6.2.2.0 - 6.2.2.0_1
  • IBM Sterling File Gateway 6.2.0.0 - 6.2.0.5_2, 6.2.1.0 - 6.2.1.1_2, 6.2.2.0 - 6.2.2.0_1

Timeline

  • 2026-07-24: advisory: Initial IBM publication
  • 2026-07-28: disclosed: NVD publication date

References

Related threats