IBM Sterling B2B Integrator and File Gateway Information Disclosure Vulnerability

Vulnerability

An information disclosure vulnerability has been identified in IBM Sterling B2B Integrator versions 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4, as well as in IBM Sterling File Gateway versions 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4. This vulnerability could allow a privileged user to access sensitive system information about the server, potentially facilitating further attacks against the system.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive system information, which could be used to launch additional attacks against the server.

Remediation

Users can upgrade to IBM Sterling B2B Integrator or IBM Sterling File Gateway versions 6.1.2.7_2, 6.2.0.5, or 6.2.1.1. The IIM versions of these releases are available on Fix Central, while the container versions can be found in the IBM Entitled Registry.

Added: Sep 4, 2025, 3:21 PM
Updated: Sep 4, 2025, 5:56 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
2.5
exploitability
4.4
remediation
7.7
relevance
0.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.