cbcvebase.

Ibm Sterling File Gateway vulnerabilities

110 known vulnerabilities affecting ibm/sterling_file_gateway.

Total CVEs
110
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH14MEDIUM89LOW5

Vulnerabilities

Page 4 of 6
CVE-2025-3630P4MEDIUMCVSS 5.4≥ 6.0.0.0, < 6.1.2.7_1≥ 6.2.0.0, < 6.2.0.5+2 more2025-07-08
CVE-2025-3630 [MEDIUM] CWE-79 CVE-2025-3630: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gate IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially l
nvd
CVE-2020-4564P4MEDIUMCVSS 5.4≥ 2.2.0.0, ≤ 6.0.3.1v2.2.0.0+1 more2020-10-20
CVE-2020-4564 [MEDIUM] CWE-79 CVE-2020-4564: IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 and IBM Sterling File Gateway 2 IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 and IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sessio
nvd
CVE-2019-4280P4MEDIUMCVSS 5.3≥ 2.2.0.0, ≤ 6.0.1.0v2.2.0.0+1 more2019-09-30
CVE-2019-4280 [MEDIUM] CWE-319 CVE-2019-4280: IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 displays sensitive information in HTTP requests wh IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 displays sensitive information in HTTP requests which could be used in further attacks against the system. IBM X-Force ID: 160503.
nvd
CVE-2021-20484P4MEDIUMCVSS 5.4≥ 2.2.0.0, ≤ 6.1.0.3v2.2.0.0+1 more2021-09-23
CVE-2021-20484 [MEDIUM] CWE-79 CVE-2021-20484: IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 is vulnerable to cross-site scripting. This vulner IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 197666.
nvd
CVE-2023-47714P4MEDIUMCVSS 5.4≥ 6.0.0.0, ≤ 6.0.3.9≥ 6.1.0.0, ≤ 6.1.2.3+1 more2024-04-12
CVE-2023-47714 [MEDIUM] CWE-79 CVE-2023-47714: IBM Sterling File Gateway 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerabl IBM Sterling File Gateway 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 271531.
nvd
CVE-2023-52292P4MEDIUMCVSS 5.4≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2.0.0, ≤ 6.2.0.32025-01-27
CVE-2023-52292 [MEDIUM] CWE-79 CVE-2023-52292: IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to store IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2025-2667P4MEDIUMCVSS 4.9≥ 6.0.0.0, < 6.1.2.7_2≥ 6.2.0.0, < 6.2.0.5+2 more2025-09-04
CVE-2025-2667 [MEDIUM] CWE-497 CVE-2025-2667: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling F IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 could disclose sensitive system information about the server to a privileged user that could aid in further attacks against the system.
nvd
CVE-2014-6199P4MEDIUMCVSS 5.0v2.1v2.22015-01-10
CVE-2014-6199 [MEDIUM] CWE-399 CVE-2014-6199: The HTTP Server Adapter in IBM Sterling B2B Integrator 5.1 and 5.2.x and Sterling File Gateway 2.1 a The HTTP Server Adapter in IBM Sterling B2B Integrator 5.1 and 5.2.x and Sterling File Gateway 2.1 and 2.2 allows remote attackers to cause a denial of service (connection-slot exhaustion) via a crafted HTTP request.
nvd
CVE-2017-1549P4MEDIUMCVSS 5.4v2.22017-12-11
CVE-2017-1549 [MEDIUM] CWE-79 CVE-2017-1549: IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131289.
nvd
CVE-2017-1632P4MEDIUMCVSS 5.4v2.22017-12-11
CVE-2017-1632 [MEDIUM] CWE-79 CVE-2017-1632: IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133178.
nvd
CVE-2013-0481P4MEDIUMCVSS 5.0v2.1v2.22013-07-03
CVE-2013-0481 [MEDIUM] CWE-200 CVE-2013-0481: The console in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows The console in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to read stack traces by triggering (1) an error or (2) an exception.
nvd
CVE-2017-1575P4MEDIUMCVSS 5.5≥ 2.2.0, ≤ 2.2.6v2.2.0+1 more2018-07-20
CVE-2017-1575 [MEDIUM] CWE-327 CVE-2017-1575: IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) uses we IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) uses weaker than expected cryptographic algorithms that could allow a local attacker to decrypt highly sensitive information. IBM X-Force ID: 132032.
nvd
CVE-2018-1470P4MEDIUMCVSS 4.3≥ 2.2.0, ≤ 2.2.6v2.2.0+1 more2018-07-20
CVE-2018-1470 [MEDIUM] CWE-200 CVE-2018-1470: IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote authenticated attacker to obtain IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote authenticated attacker to obtain sensitive information displayed in the URL that could lead to further attacks against the system. IBM X-Force ID: 140688.
nvd
CVE-2023-47159P4MEDIUMCVSS 4.3≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2.0.0, ≤ 6.2.0.12025-01-27
CVE-2023-47159 [MEDIUM] CWE-204 CVE-2023-47159: IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authent IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to enumerate usernames due to an observable discrepancy in request responses.
nvd
CVE-2013-5407P4MEDIUMCVSS 4.9v2.22013-12-21
CVE-2013-5407 [MEDIUM] CWE-20 CVE-2013-5407: IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not properly restrict use of FRAME IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not properly restrict use of FRAME elements, which allows remote authenticated users to bypass intended access restrictions or obtain sensitive information via a crafted web site, related to a "frame injection" issue.
nvd
CVE-2026-7775P4MEDIUMCVSS 4.8≥ 6.2.0.0, ≤ 6.2.0.6≥ 6.2.1.0, ≤ 6.2.1.1_2+1 more2026-07-28
CVE-2026-7775 [MEDIUM] CWE-79 CVE-2026-7775: IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the W
nvd
CVE-2021-20563P4MEDIUMCVSS 4.3≥ 2.2.0.0, ≤ 6.1.0.3v2.2.0.0+1 more2021-09-23
CVE-2021-20563 [MEDIUM] CVE-2021-20563: IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote authenciated user to obtain s IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote authenciated user to obtain sensitive information. By sending a specially crafted request, the user could disclose a valid filepath on the server which could be used in further attacks against the system. IBM X-Force ID: 199234.
nvd
CVE-2026-3157P4MEDIUMCVSS 4.3≥ 6.2.0.0, ≤ 6.2.0.5_2≥ 6.2.1.0, ≤ 6.2.1.1_2+1 more2026-07-28
CVE-2026-3157 [MEDIUM] CWE-615 CVE-2026-3157: IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 throug IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to an information disclosure due to sensitive information being included in the source code comments of a mailbox
nvd
CVE-2026-3158P4MEDIUMCVSS 4.3≥ 6.2.0.0, ≤ 6.2.0.5_2≥ 6.2.1.0, ≤ 6.2.1.1_2+1 more2026-07-28
CVE-2026-3158 [MEDIUM] CWE-615 CVE-2026-3158: IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 throug IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to an information disclosure due to sensitive information being included in the source code comments of a dashboa
nvd
CVE-2012-5936P4MEDIUMCVSS 5.0v2.1v2.22013-07-03
CVE-2012-5936 [MEDIUM] CWE-310 CVE-2012-5936: IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not set the secure IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
nvd
Ibm Sterling File Gateway vulnerabilities | cvebase