Ibm Sterling File Gateway vulnerabilities
110 known vulnerabilities affecting ibm/sterling_file_gateway.
Total CVEs
110
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH14MEDIUM89LOW5
Vulnerabilities
Page 1 of 6
CVE-2026-75878P2CRITICALCVSS 9.1≥ 6.2.0.0, ≤ 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.12026-09-18
CVE-2026-75878 [CRITICAL] CWE-287 CVE-2026-75878: IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully
IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.
nvd
CVE-2026-7253P3HIGHCVSS 8.8≥ 6.2.1.0, ≤ 6.2.1.1_2≥ 6.2.2.0, ≤ 6.2.2.0_12026-06-22
CVE-2026-7253 [HIGH] CWE-89 CVE-2026-7253: IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privile
IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
nvd
CVE-2026-7769P3HIGHCVSS 8.1≥ 6.2.0.0, ≤ 6.2.0.5_2≥ 6.2.1.0, ≤ 6.2.1.1_2+1 more2026-07-28
CVE-2026-7769 [HIGH] CWE-89 CVE-2026-7769: IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 throug
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to v
nvd
CVE-2018-1563P4MEDIUMCVSS 5.4PoC≥ 2.2.0, ≤ 2.2.6v2.2.0+1 more2018-07-20
CVE-2018-1563 [MEDIUM] CWE-79 CVE-2018-1563: IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) is vuln
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142967.
nvd
CVE-2020-4647P3HIGHCVSS 8.8≥ 2.2.0.0, ≤ 2.2.6.5≥ 6.0.0.0, ≤ 6.0.3.2+4 more2020-11-16
CVE-2020-4647 [HIGH] CWE-89 CVE-2020-4647: IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 is vulnerable to SQL i
IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
nvd
CVE-2012-5937P3CRITICALCVSS 9.3v1.1v2.0+2 more2013-04-12
CVE-2012-5937 [CRITICAL] CVE-2012-5937: Unspecified vulnerability in the CLA2 server in IBM Gentran Integration Suite 4.3, Sterling Integrat
Unspecified vulnerability in the CLA2 server in IBM Gentran Integration Suite 4.3, Sterling Integrator 5.0 and 5.1, and Sterling B2B Integrator 5.2, as used in IBM Sterling File Gateway 1.1 through 2.2 and other products, allows remote attackers to execute arbitrary commands via unknown vectors.
nvd
CVE-2013-4002P3HIGHCVSS 7.1v2.1v2.22013-07-23
CVE-2013-4002 [HIGH] CVE-2013-4002: XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment
XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, Jav
nvd
CVE-2025-36368P3HIGHCVSS 7.2≥ 6.1.0.0, < 6.1.2.8≥ 6.2.0.0, < 6.2.0.5_2+1 more2026-03-13
CVE-2025-36368 [HIGH] CWE-89 CVE-2025-36368: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, and 6.2.1.0 through 6.2.1.1_1 are vulnerable to SQL injection. An administrative user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
nvd
CVE-2014-0927P3HIGHCVSS 8.1v2.1v2.22018-04-20
CVE-2014-0927 [HIGH] CWE-287 CVE-2014-0927: The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gatew
The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to bypass authentication by leveraging knowledge of the port number and webapp path. IBM X-Force ID: 92259.
nvd
CVE-2025-14031P3HIGHCVSS 7.5≥ 6.1.0.0, < 6.1.2.8≥ 6.2.0.0, < 6.2.0.5_2+2 more2026-03-17
CVE-2025-14031 [HIGH] CWE-77 CVE-2025-14031: IBM Sterling B2B Integrator and and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 thr
IBM Sterling B2B Integrator and and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 could allow an unauthenticated attacker to send a specially crafted request that causes the application to crash.
nvd
CVE-2021-20584P3HIGHCVSS 7.5v2.2.0.0v6.0.1.0+6 more2021-10-07
CVE-2021-20584 [HIGH] CVE-2021-20584: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote attacker to upload arbitrary
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote attacker to upload arbitrary files, caused by improper access controls. IBM X-Force ID: 199397.
nvd
CVE-2019-4147P3HIGHCVSS 7.2≥ 2.2, ≤ 6.0.1.0v2.2.0.0+1 more2019-09-16
CVE-2019-4147 [HIGH] CWE-89 CVE-2019-4147: IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 is vulnerable to SQL injection. A remote attacker
IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 158413.
nvd
CVE-2026-19290P3HIGHCVSS 7.5≥ 6.2.0.0, ≤ 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.12026-09-14
CVE-2026-19290 [HIGH] CWE-284 CVE-2026-19290: IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 could allo
IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 could allow a remote attacker to obtain sensitive information due to improper access control.
nvd
CVE-2025-36134P3HIGHCVSS 7.5≥ 6.0.0.0, < 6.1.2.7_2≥ 6.2.0.0, < 6.2.0.5_1+3 more2025-11-25
CVE-2025-36134 [HIGH] CWE-1275 CVE-2025-36134: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 throug
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie.
nvd
CVE-2026-1264P3MEDIUMCVSS 6.5≥ 6.1.0.0, < 6.1.2.8≥ 6.2.0.0, < 6.2.0.5_2+2 more2026-03-17
CVE-2026-1264 [MEDIUM] CWE-306 CVE-2026-1264: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 allows a remote unauthenticated attacker to view and delete the partners of a community and to delete the communities.
nvd
CVE-2015-0194P3MEDIUMCVSS 6.5v2.1v2.22017-08-02
CVE-2015-0194 [MEDIUM] CWE-611 CVE-2015-0194: XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling
XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling File Gateway 2.1 and 2.2 allows remote attackers to read arbitrary files via a crafted XML data.
nvd
CVE-2021-20489P3HIGHCVSS 8.8≥ 2.2.0.0, ≤ 5.2.6.5_3≥ 6.0.0.0, ≤ 6.0.0.6+10 more2021-10-07
CVE-2021-20489 [HIGH] CWE-352 CVE-2021-20489: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 197790.
nvd
CVE-2020-4476P3HIGHCVSS 7.5≥ 2.2.0.0, ≤ 2.2.6.5≥ 6.0.0.0, ≤ 6.0.3.2+4 more2020-11-16
CVE-2020-4476 [HIGH] CVE-2020-4476: IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 could allow a remote a
IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 181778.
nvd
CVE-2026-7362P3MEDIUMCVSS 6.5≥ 6.2.1.0, ≤ 6.2.1.1_2≥ 6.2.2.0, ≤ 6.2.2.0_12026-07-28
CVE-2026-7362 [MEDIUM] CWE-284 CVE-2026-7362: IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterlin
IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 could allow an authenticated user to obtain sensitive information that should only be available to a privileged user.
nvd
CVE-2025-14483P3MEDIUMCVSS 6.5≥ 6.1.0.0, < 6.1.2.8≥ 6.2.0.0, < 6.2.0.5_2+2 more2026-03-13
CVE-2025-14483 [MEDIUM] CWE-201 CVE-2025-14483: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 could disclose sensitive host information to authenticated users in responses that could be used in further attacks against the system.
nvd
1 / 6Next →