Ibm Sterling File Gateway vulnerabilities
110 known vulnerabilities affecting ibm/sterling_file_gateway.
Total CVEs
110
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH14MEDIUM89LOW5
Vulnerabilities
Page 4 of 6
CVE-2025-3630P4MEDIUMCVSS 5.4≥ 6.0.0.0, < 6.1.2.7_1≥ 6.2.0.0, < 6.2.0.5+2 more2025-07-08
CVE-2025-3630 [MEDIUM] CWE-79 CVE-2025-3630: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gate
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway
6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4
is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially l
nvd
CVE-2020-4564P4MEDIUMCVSS 5.4≥ 2.2.0.0, ≤ 6.0.3.1v2.2.0.0+1 more2020-10-20
CVE-2020-4564 [MEDIUM] CWE-79 CVE-2020-4564: IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 and IBM Sterling File Gateway 2
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 and IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sessio
nvd
CVE-2019-4280P4MEDIUMCVSS 5.3≥ 2.2.0.0, ≤ 6.0.1.0v2.2.0.0+1 more2019-09-30
CVE-2019-4280 [MEDIUM] CWE-319 CVE-2019-4280: IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 displays sensitive information in HTTP requests wh
IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 displays sensitive information in HTTP requests which could be used in further attacks against the system. IBM X-Force ID: 160503.
nvd
CVE-2021-20484P4MEDIUMCVSS 5.4≥ 2.2.0.0, ≤ 6.1.0.3v2.2.0.0+1 more2021-09-23
CVE-2021-20484 [MEDIUM] CWE-79 CVE-2021-20484: IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 is vulnerable to cross-site scripting. This vulner
IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 197666.
nvd
CVE-2023-47714P4MEDIUMCVSS 5.4≥ 6.0.0.0, ≤ 6.0.3.9≥ 6.1.0.0, ≤ 6.1.2.3+1 more2024-04-12
CVE-2023-47714 [MEDIUM] CWE-79 CVE-2023-47714: IBM Sterling File Gateway 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerabl
IBM Sterling File Gateway 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 271531.
nvd
CVE-2023-52292P4MEDIUMCVSS 5.4≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2.0.0, ≤ 6.2.0.32025-01-27
CVE-2023-52292 [MEDIUM] CWE-79 CVE-2023-52292: IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to store
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2025-2667P4MEDIUMCVSS 4.9≥ 6.0.0.0, < 6.1.2.7_2≥ 6.2.0.0, < 6.2.0.5+2 more2025-09-04
CVE-2025-2667 [MEDIUM] CWE-497 CVE-2025-2667: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling F
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 could disclose sensitive system information about the server to a privileged user that could aid in further attacks against the system.
nvd
CVE-2014-6199P4MEDIUMCVSS 5.0v2.1v2.22015-01-10
CVE-2014-6199 [MEDIUM] CWE-399 CVE-2014-6199: The HTTP Server Adapter in IBM Sterling B2B Integrator 5.1 and 5.2.x and Sterling File Gateway 2.1 a
The HTTP Server Adapter in IBM Sterling B2B Integrator 5.1 and 5.2.x and Sterling File Gateway 2.1 and 2.2 allows remote attackers to cause a denial of service (connection-slot exhaustion) via a crafted HTTP request.
nvd
CVE-2017-1549P4MEDIUMCVSS 5.4v2.22017-12-11
CVE-2017-1549 [MEDIUM] CWE-79 CVE-2017-1549: IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users
IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131289.
nvd
CVE-2017-1632P4MEDIUMCVSS 5.4v2.22017-12-11
CVE-2017-1632 [MEDIUM] CWE-79 CVE-2017-1632: IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users
IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133178.
nvd
CVE-2013-0481P4MEDIUMCVSS 5.0v2.1v2.22013-07-03
CVE-2013-0481 [MEDIUM] CWE-200 CVE-2013-0481: The console in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows
The console in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to read stack traces by triggering (1) an error or (2) an exception.
nvd
CVE-2017-1575P4MEDIUMCVSS 5.5≥ 2.2.0, ≤ 2.2.6v2.2.0+1 more2018-07-20
CVE-2017-1575 [MEDIUM] CWE-327 CVE-2017-1575: IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) uses we
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) uses weaker than expected cryptographic algorithms that could allow a local attacker to decrypt highly sensitive information. IBM X-Force ID: 132032.
nvd
CVE-2018-1470P4MEDIUMCVSS 4.3≥ 2.2.0, ≤ 2.2.6v2.2.0+1 more2018-07-20
CVE-2018-1470 [MEDIUM] CWE-200 CVE-2018-1470: IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote authenticated attacker to obtain
IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote authenticated attacker to obtain sensitive information displayed in the URL that could lead to further attacks against the system. IBM X-Force ID: 140688.
nvd
CVE-2023-47159P4MEDIUMCVSS 4.3≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2.0.0, ≤ 6.2.0.12025-01-27
CVE-2023-47159 [MEDIUM] CWE-204 CVE-2023-47159: IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authent
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to enumerate usernames due to an observable discrepancy in request responses.
nvd
CVE-2013-5407P4MEDIUMCVSS 4.9v2.22013-12-21
CVE-2013-5407 [MEDIUM] CWE-20 CVE-2013-5407: IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not properly restrict use of FRAME
IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not properly restrict use of FRAME elements, which allows remote authenticated users to bypass intended access restrictions or obtain sensitive information via a crafted web site, related to a "frame injection" issue.
nvd
CVE-2026-7775P4MEDIUMCVSS 4.8≥ 6.2.0.0, ≤ 6.2.0.6≥ 6.2.1.0, ≤ 6.2.1.1_2+1 more2026-07-28
CVE-2026-7775 [MEDIUM] CWE-79 CVE-2026-7775: IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the W
nvd
CVE-2021-20563P4MEDIUMCVSS 4.3≥ 2.2.0.0, ≤ 6.1.0.3v2.2.0.0+1 more2021-09-23
CVE-2021-20563 [MEDIUM] CVE-2021-20563: IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote authenciated user to obtain s
IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote authenciated user to obtain sensitive information. By sending a specially crafted request, the user could disclose a valid filepath on the server which could be used in further attacks against the system. IBM X-Force ID: 199234.
nvd
CVE-2026-3157P4MEDIUMCVSS 4.3≥ 6.2.0.0, ≤ 6.2.0.5_2≥ 6.2.1.0, ≤ 6.2.1.1_2+1 more2026-07-28
CVE-2026-3157 [MEDIUM] CWE-615 CVE-2026-3157: IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 throug
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to an information disclosure due to sensitive information being included in the source code comments of a mailbox
nvd
CVE-2026-3158P4MEDIUMCVSS 4.3≥ 6.2.0.0, ≤ 6.2.0.5_2≥ 6.2.1.0, ≤ 6.2.1.1_2+1 more2026-07-28
CVE-2026-3158 [MEDIUM] CWE-615 CVE-2026-3158: IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 throug
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to an information disclosure due to sensitive information being included in the source code comments of a dashboa
nvd
CVE-2012-5936P4MEDIUMCVSS 5.0v2.1v2.22013-07-03
CVE-2012-5936 [MEDIUM] CWE-310 CVE-2012-5936: IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not set the secure
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
nvd