VendorsIBMsterling_file_gatewayall versions
Vulnerabilities

IBM Sterling Sterling File Gateway

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

102CVEs
CVE-2012-5937
Unspecified vulnerability in the CLA2 server in IBM Gentran Integration Suite 4.3, Sterling Integrator 5.0 and 5.1, and Sterling B2B Integrator 5.2, as used in IBM Sterling File Gateway 1.1 through 2.2 and other products, allows remote attackers to execute arbitrary commands via unknown vectors.
Published 2013-04-12 · Modified
9.3EPSS 0.026
CVE-2020-4647
IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
Published 2020-11-16 · Modified
8.8EPSS 0.010
CVE-2021-20489
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 197790.
Published 2021-10-07 · Modified
8.8EPSS 0.004
CVE-2014-0927
The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to bypass authentication by leveraging knowledge of the port number and webapp path. IBM X-Force ID: 92259.
Published 2018-04-20 · Modified
8.1EPSS 0.023
CVE-2026-7769
SQL injection Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway
Published 2026-07-28 · Analyzed
8.1EPSS 0.005
CVE-2017-1544
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) caches usernames and passwords in browsers that could be used by a local attacker to obtain sensitive information. IBM X-Force ID: 130812.
Published 2018-07-20 · Modified
7.8EPSS 0.004
CVE-2020-4476
IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 181778.
Published 2020-11-16 · Modified
7.5EPSS 0.015
CVE-2025-14031
IBM Sterling B2B Integrator and IBM Sterling File Gateway Denial of Service
Published 2026-03-17 · Analyzed
7.5EPSS 0.003
CVE-2025-36134
IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure
Published 2025-11-25 · Analyzed
7.5EPSS 0.003
CVE-2019-4147
IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 158413.
Published 2019-09-16 · Modified
7.2EPSS 0.013
CVE-2025-36368
IBM Sterling B2B Integrator and IBM Sterling File Gateway SQL Injection
Published 2026-03-13 · Analyzed
7.2EPSS 0.003
CVE-2013-4002
XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, Java SE Embedded 7u40 and earlier, and possibly other products allows remote attackers to cause a denial of service via vectors related to XML attribute names.
Published 2013-07-23 · Modified
7.1EPSS 0.247
CVE-2026-1264
IBM Sterling B2B Integrator and IBM Sterling File Gateway Improper Access Controls
Published 2026-03-17 · Analyzed
7.1EPSS 0.002
CVE-2013-2984
Directory traversal vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote authenticated users to read or modify files via unspecified vectors.
Published 2013-07-03 · Modified
6.5EPSS 0.015
CVE-2015-0194
XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling File Gateway 2.1 and 2.2 allows remote attackers to read arbitrary files via a crafted XML data.
Published 2017-08-02 · Modified
6.5EPSS 0.014
CVE-2017-1550
IBM Sterling File Gateway 2.2 could allow an authenticated user to change other user's passwords. IBM X-Force ID: 131290.
Published 2017-12-11 · Modified
6.5EPSS 0.012
CVE-2017-1487
IBM Sterling File Gateway 2.2 could allow an authenticated attacker to obtain sensitive information such as login ids on the system. IBM X-Force ID: 128626.
Published 2017-12-07 · Modified
6.5EPSS 0.011
CVE-2013-2982
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to upload arbitrary files via unspecified vectors.
Published 2013-07-03 · Modified
6.5EPSS 0.011
CVE-2012-5766
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to execute arbitrary SQL commands via vectors involving the RNVisibility page and unspecified screens, a different vulnerability than CVE-2013-0560.
Published 2013-07-03 · Modified
6.5EPSS 0.010
CVE-2013-5409
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Published 2013-12-21 · Modified
6.5EPSS 0.010
CVE-2013-0560
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2012-5766.
Published 2013-07-03 · Modified
6.5EPSS 0.010
CVE-2020-4259
IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 could allow an authenticated user could manipulate cookie information and remove or add modules from the cookie to access functionality not authorized to. IBM X-Force ID: 175638.
Published 2020-05-14 · Modified
6.5EPSS 0.008
CVE-2020-4654
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensitive information due to improper permission control. IBM X-Force ID: 186090.
Published 2021-10-08 · Modified
6.5EPSS 0.007
CVE-2021-20473
IBM Sterling File Gateway User Interface 2.2.0.0 through 6.1.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 196944.
Published 2021-10-07 · Modified
6.5EPSS 0.005
CVE-2026-7362
Improper Access Control Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway
Published 2026-07-28 · Analyzed
6.5EPSS 0.003
CVE-2025-2988
IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure
Published 2025-08-19 · Analyzed
6.5EPSS 0.003
CVE-2025-14483
IBM Sterling B2B Integrator and IBM Sterling File Gateway Information Disclosure
Published 2026-03-13 · Analyzed
6.5EPSS 0.002
CVE-2013-0476
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to inject arbitrary FTP commands via unspecified vectors.
Published 2013-07-03 · Modified
6.4EPSS 0.011
CVE-2023-52292
IBM Sterling File Gateway cross-site scripting
Published 2025-01-27 · Analyzed
6.4EPSS 0.002
CVE-2025-3630
IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting
Published 2025-07-08 · Analyzed
6.4EPSS 0.002
CVE-2020-4658
IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186095.
Published 2020-12-16 · Modified
6.1EPSS 0.007
CVE-2021-20481
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 197503.
Published 2021-10-07 · Modified
6.1EPSS 0.006
CVE-2025-33014
IBM Sterling B2B Integrator and IBM Sterling File Gateway link injection
Published 2025-07-18 · Analyzed
6.1EPSS 0.002
CVE-2017-1575
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) uses weaker than expected cryptographic algorithms that could allow a local attacker to decrypt highly sensitive information. IBM X-Force ID: 132032.
Published 2018-07-20 · Modified
5.5EPSS 0.002
CVE-2026-7775
Cross-site Scripting Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway
Published 2026-07-28 · Analyzed
5.5EPSS 0.002
CVE-2025-1349
IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting
Published 2025-06-18 · Analyzed
5.5EPSS 0.002
CVE-2025-36002
IBM Sterling B2B Integrator information disclosure
Published 2025-10-16 · Modified
5.5EPSS 0.002
CVE-2018-1563
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142967.
Published 2018-07-20 · Modified
5.41 PoCEPSS 0.028
CVE-2017-1549
IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131289.
Published 2017-12-11 · Modified
5.4EPSS 0.008
CVE-2020-4564
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 and IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 183933.
Published 2020-10-20 · Modified
5.4EPSS 0.007
1 / 3Next →