cbcvebase.

Ibm Sterling File Gateway vulnerabilities

110 known vulnerabilities affecting ibm/sterling_file_gateway.

Total CVEs
110
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH14MEDIUM89LOW5

Vulnerabilities

Page 3 of 6
CVE-2025-36298P4MEDIUMCVSS 5.4≥ 6.1.2.0, ≤ 6.1.2.7_2≥ 6.2.0.0, ≤ 6.2.0.5_2+2 more2026-07-30
CVE-2025-36298 [MEDIUM] CWE-79 CVE-2025-36298: IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6. IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 Ebics server component is vulnerable to cross-site scripting. This vulne
nvd
CVE-2025-36112P4MEDIUMCVSS 5.3≥ 6.0.0.0, < 6.1.2.7_2≥ 6.2.0.0, < 6.2.0.5_1+3 more2025-11-24
CVE-2025-36112 [MEDIUM] CWE-497 CVE-2025-36112: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 throug IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could reveal sensitive server IP configuration information to an unauthorized user.
nvd
CVE-2013-0476P4MEDIUMCVSS 6.4v2.1v2.22013-07-03
CVE-2013-0476 [MEDIUM] CVE-2013-0476: IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to inject arbitrary FTP commands via unspecified vectors.
nvd
CVE-2025-36002P4MEDIUMCVSS 5.5≥ 6.2.0.0, < 6.2.0.5_1v6.2.1.0+1 more2025-10-16
CVE-2025-36002 [MEDIUM] CWE-260 CVE-2025-36002: IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0 IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5, and 6.2.1.0 stores user credentials in configuration files which can be read by a local user.
nvd
CVE-2025-36431P4MEDIUMCVSS 5.4≥ 6.2.2.0, ≤ 6.2.2.0_12026-07-30
CVE-2025-36431 [MEDIUM] CWE-79 CVE-2025-36431: IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through 6.2.2.0_1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted ses
nvd
CVE-2026-0835P4MEDIUMCVSS 5.4≥ 6.1.0.0, < 6.1.2.8≥ 6.2.0.0, < 6.2.0.5_2+2 more2026-03-13
CVE-2026-0835 [MEDIUM] CWE-79 CVE-2026-0835: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 are vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cr
nvd
CVE-2025-14504P4MEDIUMCVSS 5.4≥ 6.1.0.0, < 6.1.2.8≥ 6.2.0.0, < 6.2.0.5_2+5 more2026-03-13
CVE-2025-14504 [MEDIUM] CWE-79 CVE-2025-14504: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c
nvd
CVE-2025-36348P4MEDIUMCVSS 4.9≥ 6.1.0.0, < 6.1.2.8≥ 6.2.0.0, < 6.2.0.5_1+4 more2026-02-17
CVE-2025-36348 [MEDIUM] CWE-209 CVE-2025-36348: IBM Sterling B2B Integrator versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 IBM Sterling B2B Integrator versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1, and IBM Sterling File Gateway versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1 may expose sensitive information to a remote privileged attacker due to the application returning detailed technic
nvd
CVE-2025-33008P4MEDIUMCVSS 5.4v6.2.1.02025-08-19
CVE-2025-33008 [MEDIUM] CWE-79 CVE-2025-33008: IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File Gateway 6.2.1.0 is vulnerable to cross-sit IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File Gateway 6.2.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2023-40693P4MEDIUMCVSS 5.4≥ 6.1.0.0, < 6.1.2.8≥ 6.2.0.0, < 6.2.0.5_2+1 more2026-03-13
CVE-2023-40693 [MEDIUM] CWE-79 CVE-2023-40693: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, and 6.2.0.0 thr IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, and 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wi
nvd
CVE-2024-54183P4MEDIUMCVSS 5.4≥ 6.0.0.0, < 6.1.2.7≥ 6.2.0.0, < 6.2.0.52025-06-18
CVE-2024-54183 [MEDIUM] CWE-79 CVE-2024-54183: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 throug IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted se
nvd
CVE-2025-2793P4MEDIUMCVSS 5.4≥ 6.0.0.0, < 6.1.2.7_1≥ 6.2.0.0, < 6.2.0.5+2 more2025-07-08
CVE-2025-2793 [MEDIUM] CWE-79 CVE-2025-2793: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gate IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadi
nvd
CVE-2025-36135P4MEDIUMCVSS 5.4≥ 6.0.0.0, ≤ 6.1.2.7_1≥ 6.2.0.0, ≤ 6.2.0.5+1 more2025-11-07
CVE-2025-36135 [MEDIUM] CWE-79 CVE-2025-36135: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended func
nvd
CVE-2024-47109P4MEDIUMCVSS 5.3≥ 6.0.0.0, < 6.1.2.7≥ 6.2.0.0, < 6.2.0.4+2 more2025-03-10
CVE-2024-47109 [MEDIUM] CWE-522 CVE-2024-47109: IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure th IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure the installation path of the server which could aid in further attacks against the system.
nvd
CVE-2026-1918P4MEDIUMCVSS 4.9≥ 6.2.0.0, ≤ 6.2.0.5_2≥ 6.2.1.0, ≤ 6.2.1.1_2+1 more2026-07-28
CVE-2026-1918 [MEDIUM] CWE-532 CVE-2026-1918: IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 throug IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 stores potentially sensitive information in log files that could be read by a privileged user.
nvd
CVE-2020-4658P4MEDIUMCVSS 6.1≥ 2.2.0.0, ≤ 6.0.3.2v2.2.0.0+1 more2020-12-16
CVE-2020-4658 [MEDIUM] CWE-79 CVE-2020-4658: IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulner IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186095.
nvd
CVE-2021-20561P4MEDIUMCVSS 6.1v2.2.0.0v6.0.1.0+6 more2021-10-07
CVE-2021-20561 [MEDIUM] CWE-79 CVE-2021-20561: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulner IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199230.
nvd
CVE-2021-20481P4MEDIUMCVSS 6.1≥ 2.2.0.0, ≤ 5.2.6.5_3≥ 6.0.0.0, ≤ 6.0.0.6+10 more2021-10-07
CVE-2021-20481 [MEDIUM] CWE-79 CVE-2021-20481: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulner IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 197503.
nvd
CVE-2014-0912P4MEDIUMCVSS 5.3v2.1v2.22018-04-20
CVE-2014-0912 [MEDIUM] CWE-200 CVE-2014-0912: IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to obtain sensitive product information via vectors related to an error page. IBM X-Force ID: 92072.
nvd
CVE-2021-39086P4MEDIUMCVSS 5.3≥ 6.0.0.0, < 6.0.3.6≥ 6.1.0.0, < 6.1.0.5+7 more2022-08-16
CVE-2021-39086 [MEDIUM] CWE-209 CVE-2021-39086: IBM Sterling File Gateway 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1. IBM Sterling File Gateway 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 215889.
nvd
Ibm Sterling File Gateway vulnerabilities | cvebase