VendorsIBMsterling_file_gatewayany version
Vulnerabilities

IBM Sterling Sterling File Gateway any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

63CVEs
CVE-2019-4280
IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 displays sensitive information in HTTP requests which could be used in further attacks against the system. IBM X-Force ID: 160503.
Published 2019-09-30 · Modified
5.3EPSS 0.008
CVE-2026-3482
IBM Sterling B2B Integrator and IBM Sterling File Gateway Authorization Bypass
Published 2026-07-22 · Analyzed
5.3EPSS 0.005
CVE-2024-47109
IBM Sterling File Gateway information disclosure
Published 2025-03-10 · Analyzed
5.3EPSS 0.003
CVE-2025-36112
IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure
Published 2025-11-24 · Analyzed
5.3EPSS 0.002
CVE-2026-1918
IBM Sterling B2B Integrator and IBM Sterling File Gateway store sensitive information in a log file
Published 2026-07-28 · Analyzed
4.9EPSS 0.004
CVE-2025-36348
The Dashboard of IBM Sterling B2B Integrator and IBM Sterling File Gateway is Vulnerable to Information Disclosure
Published 2026-02-17 · Analyzed
4.9EPSS 0.003
CVE-2025-2667
IBM Sterling B2B Integrator information disclosure
Published 2025-09-04 · Analyzed
4.9EPSS 0.003
CVE-2025-2694
IBM Sterling B2B Integrator cross-site scripting
Published 2025-09-04 · Analyzed
4.8EPSS 0.002
CVE-2018-1470
IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote authenticated attacker to obtain sensitive information displayed in the URL that could lead to further attacks against the system. IBM X-Force ID: 140688.
Published 2018-07-20 · Modified
4.3EPSS 0.018
CVE-2020-4665
IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 186280.
Published 2020-11-16 · Modified
4.3EPSS 0.010
CVE-2020-4763
IBM Sterling File Gateway 6.0.0.0 through 6.0.3.2 and 2.2.0.0 through 2.2.6.5 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 188897.
Published 2020-11-16 · Modified
4.3EPSS 0.010
CVE-2020-4299
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 could expose sensitive information to a user through a specially crafted HTTP request. IBM X-Force ID: 176606.
Published 2020-05-14 · Modified
4.3EPSS 0.010
CVE-2021-20485
IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 197667.
Published 2021-09-23 · Modified
4.3EPSS 0.010
CVE-2021-20552
IBM Sterling File Gateway 6.0.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199170.
Published 2021-10-07 · Modified
4.3EPSS 0.010
CVE-2013-0455
Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling B2B Integrator 5.2.4 and Sterling File Gateway allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2013-07-02 · Modified
4.3EPSS 0.009
CVE-2021-20563
IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote authenciated user to obtain sensitive information. By sending a specially crafted request, the user could disclose a valid filepath on the server which could be used in further attacks against the system. IBM X-Force ID: 199234.
Published 2021-09-23 · Modified
4.3EPSS 0.007
CVE-2026-3157
Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway due to information disclosure in mailbox UI
Published 2026-07-28 · Analyzed
4.3EPSS 0.003
CVE-2026-3158
Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway due to information disclosure
Published 2026-07-28 · Analyzed
4.3EPSS 0.003
CVE-2023-47159
IBM Sterling File Gateway information disclosure
Published 2025-01-27 · Analyzed
4.3EPSS 0.003
CVE-2024-22316
IBM Sterling File Gateway improper access control
Published 2025-01-27 · Modified
4.3EPSS 0.002
CVE-2025-2827
IBM Sterling File Gateway information disclosure
Published 2025-07-08 · Analyzed
4.3EPSS 0.002
CVE-2024-54172
IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site request forgery
Published 2025-06-18 · Analyzed
4.3EPSS 0.001
CVE-2025-1348
IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure
Published 2025-06-18 · Analyzed
4.0EPSS 0.001
← Prev2 / 2