VendorsIBMsterling_file_gatewayall versions
Vulnerabilities

IBM Sterling Sterling File Gateway

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

102CVEs
CVE-2017-1632
IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133178.
Published 2017-12-11 · Modified
5.4EPSS 0.007
CVE-2021-20484
IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 197666.
Published 2021-09-23 · Modified
5.4EPSS 0.005
CVE-2023-47714
IBM Sterling File Gateway cross-site scripting
Published 2024-04-12 · Analyzed
5.4EPSS 0.003
CVE-2025-33008
IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting
Published 2025-08-19 · Analyzed
5.4EPSS 0.002
CVE-2025-36298
Security Vulnerability in Ebics server affects IBM Sterling B2B Integrator and IBM Sterling File Gateway
Published 2026-07-30 · Analyzed
5.4EPSS 0.002
CVE-2025-36431
XSS Security Vulnerability in response header affects IBM Sterling B2B Integrator and IBM Sterling File Gateway
Published 2026-07-30 · Analyzed
5.4EPSS 0.002
CVE-2025-14504
IBM Sterling B2B Integrator and IBM Sterling File Gateway Cross-Site Scripting
Published 2026-03-13 · Analyzed
5.4EPSS 0.002
CVE-2026-0835
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 are vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published 2026-03-13 · Analyzed
5.4EPSS 0.002
CVE-2023-40693
IBM Sterling B2B Integrator and IBM Sterling File Gateway Cross-Site Scripting
Published 2026-03-13 · Analyzed
5.4EPSS 0.002
CVE-2024-54183
IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting
Published 2025-06-18 · Analyzed
5.4EPSS 0.002
CVE-2025-2793
IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting
Published 2025-07-08 · Analyzed
5.4EPSS 0.002
CVE-2025-36135
IBM Sterling B2B Integrator and IBM Sterling File Gateway are Vulnerable to Cross-Site Scripting
Published 2025-11-07 · Analyzed
5.4EPSS 0.002
CVE-2019-4423
IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162769.
Published 2019-09-30 · Modified
5.3EPSS 0.027
CVE-2018-1398
IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote attacker to download certain files that could contain sensitive information. IBM X-Force ID: 138434.
Published 2018-07-20 · Modified
5.3EPSS 0.023
CVE-2017-1548
IBM Sterling File Gateway 2.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 131288.
Published 2017-12-11 · Modified
5.3EPSS 0.022
CVE-2014-0912
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to obtain sensitive product information via vectors related to an error page. IBM X-Force ID: 92072.
Published 2018-04-20 · Modified
5.3EPSS 0.017
CVE-2021-39086
IBM Sterling File Gateway 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 215889.
Published 2022-08-16 · Modified
5.3EPSS 0.009
CVE-2019-4280
IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 displays sensitive information in HTTP requests which could be used in further attacks against the system. IBM X-Force ID: 160503.
Published 2019-09-30 · Modified
5.3EPSS 0.008
CVE-2026-3482
IBM Sterling B2B Integrator and IBM Sterling File Gateway Authorization Bypass
Published 2026-07-22 · Analyzed
5.3EPSS 0.005
CVE-2024-47109
IBM Sterling File Gateway information disclosure
Published 2025-03-10 · Analyzed
5.3EPSS 0.003
CVE-2025-36112
IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure
Published 2025-11-24 · Analyzed
5.3EPSS 0.002
CVE-2014-6199
The HTTP Server Adapter in IBM Sterling B2B Integrator 5.1 and 5.2.x and Sterling File Gateway 2.1 and 2.2 allows remote attackers to cause a denial of service (connection-slot exhaustion) via a crafted HTTP request.
Published 2015-01-10 · Modified
5.0EPSS 0.020
CVE-2012-5936
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Published 2013-07-03 · Modified
5.0EPSS 0.014
CVE-2013-0481
The console in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to read stack traces by triggering (1) an error or (2) an exception.
Published 2013-07-03 · Modified
5.0EPSS 0.014
CVE-2013-0539
An unspecified third-party component in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 uses short session ID values, which makes it easier for remote attackers to hijack sessions, and consequently obtain sensitive information, via a brute-force attack.
Published 2013-07-03 · Modified
5.0EPSS 0.014
CVE-2013-0558
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to obtain sensitive information about application implementation via unspecified vectors.
Published 2013-07-03 · Modified
5.0EPSS 0.014
CVE-2013-5407
IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not properly restrict use of FRAME elements, which allows remote authenticated users to bypass intended access restrictions or obtain sensitive information via a crafted web site, related to a "frame injection" issue.
Published 2013-12-21 · Modified
4.9EPSS 0.008
CVE-2026-1918
IBM Sterling B2B Integrator and IBM Sterling File Gateway store sensitive information in a log file
Published 2026-07-28 · Analyzed
4.9EPSS 0.004
CVE-2025-36348
The Dashboard of IBM Sterling B2B Integrator and IBM Sterling File Gateway is Vulnerable to Information Disclosure
Published 2026-02-17 · Analyzed
4.9EPSS 0.003
CVE-2025-2667
IBM Sterling B2B Integrator information disclosure
Published 2025-09-04 · Analyzed
4.9EPSS 0.003
CVE-2025-2694
IBM Sterling B2B Integrator cross-site scripting
Published 2025-09-04 · Analyzed
4.8EPSS 0.002
CVE-2018-1470
IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote authenticated attacker to obtain sensitive information displayed in the URL that could lead to further attacks against the system. IBM X-Force ID: 140688.
Published 2018-07-20 · Modified
4.3EPSS 0.018
CVE-2013-5413
IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not invalidate a session upon a logout action, which allows remote attackers to bypass authentication by leveraging an unattended workstation.
Published 2013-12-21 · Modified
4.3EPSS 0.013
CVE-2013-5411
IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote attackers to inject links and trigger unintended navigation or actions via unspecified vectors.
Published 2013-12-21 · Modified
4.3EPSS 0.012
CVE-2017-1497
IBM Sterling File Gateway 2.2 could allow an unauthorized user to view files they should not have access to providing they know the directory location of the file. IBM X-Force ID: 128695.
Published 2017-12-07 · Modified
4.3EPSS 0.010
CVE-2020-4665
IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 186280.
Published 2020-11-16 · Modified
4.3EPSS 0.010
CVE-2020-4763
IBM Sterling File Gateway 6.0.0.0 through 6.0.3.2 and 2.2.0.0 through 2.2.6.5 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 188897.
Published 2020-11-16 · Modified
4.3EPSS 0.010
CVE-2020-4299
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 could expose sensitive information to a user through a specially crafted HTTP request. IBM X-Force ID: 176606.
Published 2020-05-14 · Modified
4.3EPSS 0.010
CVE-2021-20485
IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 197667.
Published 2021-09-23 · Modified
4.3EPSS 0.010
CVE-2021-20552
IBM Sterling File Gateway 6.0.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199170.
Published 2021-10-07 · Modified
4.3EPSS 0.010
← Prev2 / 3Next →