Executive brief
IBM Sterling B2B Integrator and Sterling File Gateway, which are used by organizations to manage secure file transfers and business-to-business transactions, are affected by a security vulnerability. A user with high-level administrative privileges can inject malicious scripts into the management interface. If successful, this could allow the attacker to intercept sensitive information, such as user credentials, from other legitimate users accessing the system.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the Web UI of IBM Sterling B2B Integrator and IBM Sterling File Gateway. The flaw is caused by improper neutralization of user-supplied input during web page generation (CWE-79). A remote attacker with high privileges (PR:H) can exploit this by embedding arbitrary JavaScript code into the application's interface. When other users view the affected pages, the script executes in their browser context, potentially leading to the disclosure of session credentials or unauthorized actions within a trusted session. IBM has released patches (6.2.0.6_1, 6.2.1.2, and 6.2.2.1) to address this issue.
Affected products
- IBM Sterling B2B Integrator 6.2.0.0 - 6.2.0.6, 6.2.1.0 - 6.2.1.1_2, 6.2.2.0 - 6.2.2.0_1
- IBM Sterling File Gateway 6.2.0.0 - 6.2.0.6, 6.2.1.0 - 6.2.1.1_2, 6.2.2.0 - 6.2.2.0_1
Timeline
- 2026-07-22: advisory: Initial publication by IBM
- 2026-07-28: disclosed: NVD publication date