Ibm Sterling File Gateway vulnerabilities
110 known vulnerabilities affecting ibm/sterling_file_gateway.
Total CVEs
110
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH14MEDIUM89LOW5
Vulnerabilities
Page 2 of 6
CVE-2025-2988P3MEDIUMCVSS 6.5≥ 6.0.0.0, < 6.1.2.7_1≥ 6.2.0.0, < 6.2.0.5+3 more2025-08-19
CVE-2025-2988 [MEDIUM] CWE-497 CVE-2025-2988: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6.2.0.4, and 6.2.1.0 could disclose sensitive server information to an unauthorized user that could aid in further attacks against the system.
nvd
CVE-2017-1544P4HIGHCVSS 7.8≥ 2.2.0, ≤ 2.2.6v2.2.0+1 more2018-07-20
CVE-2017-1544 [HIGH] CWE-200 CVE-2017-1544: IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) caches
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) caches usernames and passwords in browsers that could be used by a local attacker to obtain sensitive information. IBM X-Force ID: 130812.
nvd
CVE-2013-5409P4MEDIUMCVSS 6.5v2.22013-12-21
CVE-2013-5409 [MEDIUM] CWE-89 CVE-2013-5409: Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2026-19273P3MEDIUMCVSS 5.4≥ 6.2.0.0, ≤ 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.12026-09-14
CVE-2026-19273 [MEDIUM] CWE-287 CVE-2026-19273: IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 and IBM
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 Standard Edition could allow a remote authenticated attacker to bypass security restrictions due to improper authentication.
nvd
CVE-2012-5766P4MEDIUMCVSS 6.5v2.1v2.22013-07-03
CVE-2012-5766 [MEDIUM] CWE-89 CVE-2012-5766: Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to execute arbitrary SQL commands via vectors involving the RNVisibility page and unspecified screens, a different vulnerability than CVE-2013-0560.
nvd
CVE-2020-4654P4MEDIUMCVSS 6.5≥ 2.2.0.0, < 5.2.6.5_4≥ 6.0.0.0, < 6.0.3.5+7 more2021-10-08
CVE-2020-4654 [MEDIUM] CVE-2020-4654: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensit
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensitive information due to improper permission control. IBM X-Force ID: 186090.
nvd
CVE-2019-4423P4MEDIUMCVSS 5.3≥ 2.2.0.0, ≤ 6.0.1.0v2.2.0.0+1 more2019-09-30
CVE-2019-4423 [MEDIUM] CWE-22 CVE-2019-4423: IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 could allow a remote attacker to traverse director
IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162769.
nvd
CVE-2026-3482P4MEDIUMCVSS 5.3≥ 6.2.0.0, ≤ 6.2.0.5_2≥ 6.2.1.0, ≤ 6.2.1.1_2+1 more2026-07-22
CVE-2026-3482 [MEDIUM] CWE-639 CVE-2026-3482: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 throug
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 could allow an unauthenticated user to read sensitive information by bypassing authentication through a specially crafted HTTP request.
nvd
CVE-2017-1550P4MEDIUMCVSS 6.5v2.22017-12-11
CVE-2017-1550 [MEDIUM] CVE-2017-1550: IBM Sterling File Gateway 2.2 could allow an authenticated user to change other user's passwords. IB
IBM Sterling File Gateway 2.2 could allow an authenticated user to change other user's passwords. IBM X-Force ID: 131290.
nvd
CVE-2013-0560P4MEDIUMCVSS 6.5v2.1v2.22013-07-03
CVE-2013-0560 [MEDIUM] CVE-2013-0560: Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2012-5766.
nvd
CVE-2020-4259P4MEDIUMCVSS 6.5≥ 2.2.0.0, ≤ 2.2.6.5_1≥ 6.0.0.0, ≤ 6.0.3.1+2 more2020-05-14
CVE-2020-4259 [MEDIUM] CWE-276 CVE-2020-4259: IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 could allow an authenticated user could manipulate
IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 could allow an authenticated user could manipulate cookie information and remove or add modules from the cookie to access functionality not authorized to. IBM X-Force ID: 175638.
nvd
CVE-2017-1548P4MEDIUMCVSS 5.3v2.22017-12-11
CVE-2017-1548 [MEDIUM] CWE-22 CVE-2017-1548: IBM Sterling File Gateway 2.2 could allow a remote attacker to traverse directories on the system. A
IBM Sterling File Gateway 2.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 131288.
nvd
CVE-2017-1487P4MEDIUMCVSS 6.5v2.22017-12-07
CVE-2017-1487 [MEDIUM] CWE-200 CVE-2017-1487: IBM Sterling File Gateway 2.2 could allow an authenticated attacker to obtain sensitive information
IBM Sterling File Gateway 2.2 could allow an authenticated attacker to obtain sensitive information such as login ids on the system. IBM X-Force ID: 128626.
nvd
CVE-2021-20375P4MEDIUMCVSS 6.5v2.2.0.0v6.0.0.0+4 more2021-10-07
CVE-2021-20375 [MEDIUM] CVE-2021-20375: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to intercept and
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to intercept and replace a message sent by another user due to improper access controls. IBM X-Force ID: 195567.
nvd
CVE-2021-20473P4MEDIUMCVSS 6.5≥ 2.2.0.0, ≤ 5.2.6.5_3≥ 6.0.0.0, ≤ 6.0.3.4+7 more2021-10-07
CVE-2021-20473 [MEDIUM] CWE-613 CVE-2021-20473: IBM Sterling File Gateway User Interface 2.2.0.0 through 6.1.1.0 does not invalidate session after l
IBM Sterling File Gateway User Interface 2.2.0.0 through 6.1.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 196944.
nvd
CVE-2013-2982P4MEDIUMCVSS 6.5v2.1v2.22013-07-03
CVE-2013-2982 [MEDIUM] CVE-2013-2982: IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authentic
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to upload arbitrary files via unspecified vectors.
nvd
CVE-2013-5413P4MEDIUMCVSS 4.3v2.22013-12-21
CVE-2013-5413 [MEDIUM] CWE-287 CVE-2013-5413: IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not invalidate a session upon a log
IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not invalidate a session upon a logout action, which allows remote attackers to bypass authentication by leveraging an unattended workstation.
nvd
CVE-2013-2984P4MEDIUMCVSS 6.5v2.1v2.22013-07-03
CVE-2013-2984 [MEDIUM] CWE-22 CVE-2013-2984: Directory traversal vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gatew
Directory traversal vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote authenticated users to read or modify files via unspecified vectors.
nvd
CVE-2018-1398P4MEDIUMCVSS 5.3≥ 2.2.0, ≤ 2.2.6v2.2.0+1 more2018-07-20
CVE-2018-1398 [MEDIUM] CWE-200 CVE-2018-1398: IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote attacker to download certain file
IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote attacker to download certain files that could contain sensitive information. IBM X-Force ID: 138434.
nvd
CVE-2025-33014P4MEDIUMCVSS 6.1≥ 6.0.0.0, < 6.1.2.7_1≥ 6.2.0.0, < 6.2.0.5+2 more2025-07-18
CVE-2025-33014 [MEDIUM] CWE-1022 CVE-2025-33014: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 throug
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.4 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser.
nvd