Ibm Sterling File Gateway vulnerabilities
99 known vulnerabilities affecting ibm/sterling_file_gateway.
Total CVEs
99
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH12MEDIUM81LOW5
Vulnerabilities
Page 1 of 5
CVE-2026-7253P3HIGHCVSS 8.8≥ 6.2.1.0, ≤ 6.2.1.1_2≥ 6.2.2.0, ≤ 6.2.2.0_12026-06-22
CVE-2026-7253 [HIGH] CWE-89 CVE-2026-7253: IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privile
IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
nvd
CVE-2018-1563P4MEDIUMCVSS 5.4PoC≥ 2.2.0, ≤ 2.2.6v2.2.0+1 more2018-07-20
CVE-2018-1563 [MEDIUM] CWE-79 CVE-2018-1563: IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) is vuln
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142967.
nvd
CVE-2020-4647P3HIGHCVSS 8.8≥ 2.2.0.0, ≤ 2.2.6.5≥ 6.0.0.0, ≤ 6.0.3.2+4 more2020-11-16
CVE-2020-4647 [HIGH] CWE-89 CVE-2020-4647: IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 is vulnerable to SQL i
IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
nvd
CVE-2012-5937P3CRITICALCVSS 9.3v1.1v2.0+2 more2013-04-12
CVE-2012-5937 [CRITICAL] CVE-2012-5937: Unspecified vulnerability in the CLA2 server in IBM Gentran Integration Suite 4.3, Sterling Integrat
Unspecified vulnerability in the CLA2 server in IBM Gentran Integration Suite 4.3, Sterling Integrator 5.0 and 5.1, and Sterling B2B Integrator 5.2, as used in IBM Sterling File Gateway 1.1 through 2.2 and other products, allows remote attackers to execute arbitrary commands via unknown vectors.
nvd
CVE-2013-4002P3HIGHCVSS 7.1v2.1v2.22013-07-23
CVE-2013-4002 [HIGH] CVE-2013-4002: XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment
XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, Jav
nvd
CVE-2025-36368P3HIGHCVSS 7.2≥ 6.1.0.0, < 6.1.2.8≥ 6.2.0.0, < 6.2.0.5_2+1 more2026-03-13
CVE-2025-36368 [HIGH] CWE-89 CVE-2025-36368: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, and 6.2.1.0 through 6.2.1.1_1 are vulnerable to SQL injection. An administrative user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
nvd
CVE-2014-0927P3HIGHCVSS 8.1v2.1v2.22018-04-20
CVE-2014-0927 [HIGH] CWE-287 CVE-2014-0927: The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gatew
The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to bypass authentication by leveraging knowledge of the port number and webapp path. IBM X-Force ID: 92259.
nvd
CVE-2025-14031P3HIGHCVSS 7.5≥ 6.1.0.0, < 6.1.2.8≥ 6.2.0.0, < 6.2.0.5_2+2 more2026-03-17
CVE-2025-14031 [HIGH] CWE-77 CVE-2025-14031: IBM Sterling B2B Integrator and and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 thr
IBM Sterling B2B Integrator and and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 could allow an unauthenticated attacker to send a specially crafted request that causes the application to crash.
nvd
CVE-2021-20584P3HIGHCVSS 7.5v2.2.0.0v6.0.1.0+6 more2021-10-07
CVE-2021-20584 [HIGH] CVE-2021-20584: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote attacker to upload arbitrary
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote attacker to upload arbitrary files, caused by improper access controls. IBM X-Force ID: 199397.
nvd
CVE-2019-4147P3HIGHCVSS 7.2≥ 2.2, ≤ 6.0.1.0v2.2.0.0+1 more2019-09-16
CVE-2019-4147 [HIGH] CWE-89 CVE-2019-4147: IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 is vulnerable to SQL injection. A remote attacker
IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 158413.
nvd
CVE-2025-36134P3HIGHCVSS 7.5≥ 6.0.0.0, < 6.1.2.7_2≥ 6.2.0.0, < 6.2.0.5_1+3 more2025-11-25
CVE-2025-36134 [HIGH] CWE-1275 CVE-2025-36134: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 throug
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie.
nvd
CVE-2026-1264P3MEDIUMCVSS 6.5≥ 6.1.0.0, < 6.1.2.8≥ 6.2.0.0, < 6.2.0.5_2+2 more2026-03-17
CVE-2026-1264 [MEDIUM] CWE-306 CVE-2026-1264: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 allows a remote unauthenticated attacker to view and delete the partners of a community and to delete the communities.
nvd
CVE-2015-0194P3MEDIUMCVSS 6.5v2.1v2.22017-08-02
CVE-2015-0194 [MEDIUM] CWE-611 CVE-2015-0194: XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling
XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling File Gateway 2.1 and 2.2 allows remote attackers to read arbitrary files via a crafted XML data.
nvd
CVE-2021-20489P3HIGHCVSS 8.8≥ 2.2.0.0, ≤ 5.2.6.5_3≥ 6.0.0.0, ≤ 6.0.0.6+10 more2021-10-07
CVE-2021-20489 [HIGH] CWE-352 CVE-2021-20489: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 197790.
nvd
CVE-2020-4476P3HIGHCVSS 7.5≥ 2.2.0.0, ≤ 2.2.6.5≥ 6.0.0.0, ≤ 6.0.3.2+4 more2020-11-16
CVE-2020-4476 [HIGH] CVE-2020-4476: IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 could allow a remote a
IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 181778.
nvd
CVE-2025-14483P3MEDIUMCVSS 6.5≥ 6.1.0.0, < 6.1.2.8≥ 6.2.0.0, < 6.2.0.5_2+2 more2026-03-13
CVE-2025-14483 [MEDIUM] CWE-201 CVE-2025-14483: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 could disclose sensitive host information to authenticated users in responses that could be used in further attacks against the system.
nvd
CVE-2025-2988P3MEDIUMCVSS 6.5≥ 6.0.0.0, < 6.1.2.7_1≥ 6.2.0.0, < 6.2.0.5+3 more2025-08-19
CVE-2025-2988 [MEDIUM] CWE-497 CVE-2025-2988: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6.2.0.4, and 6.2.1.0 could disclose sensitive server information to an unauthorized user that could aid in further attacks against the system.
nvd
CVE-2013-5409P3MEDIUMCVSS 6.5v2.22013-12-21
CVE-2013-5409 [MEDIUM] CWE-89 CVE-2013-5409: Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2017-1544P4HIGHCVSS 7.8≥ 2.2.0, ≤ 2.2.6v2.2.0+1 more2018-07-20
CVE-2017-1544 [HIGH] CWE-200 CVE-2017-1544: IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) caches
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) caches usernames and passwords in browsers that could be used by a local attacker to obtain sensitive information. IBM X-Force ID: 130812.
nvd
CVE-2012-5766P4MEDIUMCVSS 6.5v2.1v2.22013-07-03
CVE-2012-5766 [MEDIUM] CWE-89 CVE-2012-5766: Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to execute arbitrary SQL commands via vectors involving the RNVisibility page and unspecified screens, a different vulnerability than CVE-2013-0560.
nvd
1 / 5Next →