VendorsIBMsterling_file_gatewayall versions
Vulnerabilities

IBM Sterling Sterling File Gateway

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

102CVEs
CVE-2013-0455
Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling B2B Integrator 5.2.4 and Sterling File Gateway allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2013-07-02 · Modified
4.3EPSS 0.009
CVE-2021-20563
IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote authenciated user to obtain sensitive information. By sending a specially crafted request, the user could disclose a valid filepath on the server which could be used in further attacks against the system. IBM X-Force ID: 199234.
Published 2021-09-23 · Modified
4.3EPSS 0.007
CVE-2026-3157
Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway due to information disclosure in mailbox UI
Published 2026-07-28 · Analyzed
4.3EPSS 0.003
CVE-2026-3158
Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway due to information disclosure
Published 2026-07-28 · Analyzed
4.3EPSS 0.003
CVE-2023-47159
IBM Sterling File Gateway information disclosure
Published 2025-01-27 · Analyzed
4.3EPSS 0.003
CVE-2024-22316
IBM Sterling File Gateway improper access control
Published 2025-01-27 · Modified
4.3EPSS 0.002
CVE-2025-2827
IBM Sterling File Gateway information disclosure
Published 2025-07-08 · Analyzed
4.3EPSS 0.002
CVE-2024-54172
IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site request forgery
Published 2025-06-18 · Analyzed
4.3EPSS 0.001
CVE-2013-0567
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-2987, CVE-2013-3020, CVE-2013-0568, and CVE-2013-0475.
Published 2013-07-03 · Modified
4.0EPSS 0.011
CVE-2013-0479
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not properly restrict file types and extensions, which allows remote authenticated users to bypass intended access restrictions via a crafted filename.
Published 2013-07-03 · Modified
4.0EPSS 0.010
CVE-2013-0463
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-2985, CVE-2013-2987, CVE-2013-3020, CVE-2013-0568, CVE-2013-0475, and CVE-2013-0567.
Published 2013-07-03 · Modified
4.0EPSS 0.009
CVE-2013-3020
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-2987, CVE-2013-0568, CVE-2013-0475, and CVE-2013-0567.
Published 2013-07-03 · Modified
4.0EPSS 0.009
CVE-2013-2987
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-3020, CVE-2013-0568, CVE-2013-0475, and CVE-2013-0567.
Published 2013-07-03 · Modified
4.0EPSS 0.009
CVE-2013-2985
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2987, CVE-2013-3020, CVE-2013-0568, CVE-2013-0475, and CVE-2013-0567.
Published 2013-07-03 · Modified
4.0EPSS 0.009
CVE-2013-0568
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-2987, CVE-2013-3020, CVE-2013-0475, and CVE-2013-0567.
Published 2013-07-03 · Modified
4.0EPSS 0.009
CVE-2013-0475
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-2987, CVE-2013-3020, CVE-2013-0568, and CVE-2013-0567.
Published 2013-07-03 · Modified
4.0EPSS 0.009
CVE-2013-0456
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to hijack sessions via a modified cookie path.
Published 2013-07-03 · Modified
4.0EPSS 0.008
CVE-2025-1348
IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure
Published 2025-06-18 · Analyzed
4.0EPSS 0.001
CVE-2013-5406
Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters, leading to improper interaction with the Windows MHTML protocol handler.
Published 2013-12-21 · Modified
3.5EPSS 0.009
CVE-2013-5405
Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters.
Published 2013-12-21 · Modified
3.5EPSS 0.009
CVE-2013-2983
Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling File Gateway 2.2 and Sterling B2B Integrator allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2013-0468.
Published 2013-07-02 · Modified
3.5EPSS 0.008
CVE-2013-0468
Cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-2983.
Published 2013-07-03 · Modified
3.5EPSS 0.008
← Prev3 / 3