IBM Sterling B2B Integrator and IBM Sterling File Gateway Access Control Vulnerability Allowing Community and Partner Management

Vulnerability

An access control vulnerability has been identified in IBM Sterling B2B Integrator and IBM Sterling File Gateway, versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0. This vulnerability allows remote unauthenticated attackers to view and delete partners within a community, as well as delete the communities themselves.

Impact

Exploitation of this vulnerability could lead to unauthorized modification and deletion of community and partner data within the affected applications.

Remediation

Users can upgrade to IBM Sterling B2B Integrator or IBM Sterling File Gateway versions 6.1.2.8, 6.2.0.5_2, 6.2.1.1_2 or 6.2.2.0_1. The IIM versions of these updates are available on Fix Central, and the container versions are available in the IBM Entitled Registry.

Added: Mar 17, 2026, 11:19 PM
Updated: Mar 17, 2026, 11:19 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
3.1
exploitability
7.0
remediation
7.7
relevance
4.0
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.