VendorsIBMsterling_file_gatewayany version
Vulnerabilities

IBM Sterling Sterling File Gateway any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

63CVEs
CVE-2020-4647
IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
Published 2020-11-16 · Modified
8.8EPSS 0.010
CVE-2021-20489
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 197790.
Published 2021-10-07 · Modified
8.8EPSS 0.004
CVE-2026-7769
SQL injection Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway
Published 2026-07-28 · Analyzed
8.1EPSS 0.003
CVE-2017-1544
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) caches usernames and passwords in browsers that could be used by a local attacker to obtain sensitive information. IBM X-Force ID: 130812.
Published 2018-07-20 · Modified
7.8EPSS 0.004
CVE-2020-4476
IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 181778.
Published 2020-11-16 · Modified
7.5EPSS 0.015
CVE-2025-14031
IBM Sterling B2B Integrator and IBM Sterling File Gateway Denial of Service
Published 2026-03-17 · Analyzed
7.5EPSS 0.003
CVE-2025-36134
IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure
Published 2025-11-25 · Analyzed
7.5EPSS 0.003
CVE-2019-4147
IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 158413.
Published 2019-09-16 · Modified
7.2EPSS 0.013
CVE-2025-36368
IBM Sterling B2B Integrator and IBM Sterling File Gateway SQL Injection
Published 2026-03-13 · Analyzed
7.2EPSS 0.003
CVE-2026-1264
IBM Sterling B2B Integrator and IBM Sterling File Gateway Improper Access Controls
Published 2026-03-17 · Analyzed
7.1EPSS 0.002
CVE-2020-4259
IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 could allow an authenticated user could manipulate cookie information and remove or add modules from the cookie to access functionality not authorized to. IBM X-Force ID: 175638.
Published 2020-05-14 · Modified
6.5EPSS 0.008
CVE-2020-4654
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensitive information due to improper permission control. IBM X-Force ID: 186090.
Published 2021-10-08 · Modified
6.5EPSS 0.007
CVE-2021-20473
IBM Sterling File Gateway User Interface 2.2.0.0 through 6.1.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 196944.
Published 2021-10-07 · Modified
6.5EPSS 0.005
CVE-2025-2988
IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure
Published 2025-08-19 · Analyzed
6.5EPSS 0.003
CVE-2025-14483
IBM Sterling B2B Integrator and IBM Sterling File Gateway Information Disclosure
Published 2026-03-13 · Analyzed
6.5EPSS 0.002
CVE-2026-7362
Improper Access Control Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway
Published 2026-07-28 · Analyzed
6.5EPSS 0.002
CVE-2023-52292
IBM Sterling File Gateway cross-site scripting
Published 2025-01-27 · Analyzed
6.4EPSS 0.002
CVE-2025-3630
IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting
Published 2025-07-08 · Analyzed
6.4EPSS 0.002
CVE-2020-4658
IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186095.
Published 2020-12-16 · Modified
6.1EPSS 0.007
CVE-2021-20481
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 197503.
Published 2021-10-07 · Modified
6.1EPSS 0.006
CVE-2025-33014
IBM Sterling B2B Integrator and IBM Sterling File Gateway link injection
Published 2025-07-18 · Analyzed
6.1EPSS 0.002
CVE-2017-1575
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) uses weaker than expected cryptographic algorithms that could allow a local attacker to decrypt highly sensitive information. IBM X-Force ID: 132032.
Published 2018-07-20 · Modified
5.5EPSS 0.002
CVE-2025-1349
IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting
Published 2025-06-18 · Analyzed
5.5EPSS 0.002
CVE-2025-36002
IBM Sterling B2B Integrator information disclosure
Published 2025-10-16 · Modified
5.5EPSS 0.002
CVE-2026-7775
Cross-site Scripting Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway
Published 2026-07-28 · Analyzed
5.5EPSS 0.001
CVE-2018-1563
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142967.
Published 2018-07-20 · Modified
5.41 PoCEPSS 0.028
CVE-2020-4564
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 and IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 183933.
Published 2020-10-20 · Modified
5.4EPSS 0.007
CVE-2021-20484
IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 197666.
Published 2021-09-23 · Modified
5.4EPSS 0.005
CVE-2023-47714
IBM Sterling File Gateway cross-site scripting
Published 2024-04-12 · Analyzed
5.4EPSS 0.003
CVE-2025-14504
IBM Sterling B2B Integrator and IBM Sterling File Gateway Cross-Site Scripting
Published 2026-03-13 · Analyzed
5.4EPSS 0.002
CVE-2026-0835
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 are vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published 2026-03-13 · Analyzed
5.4EPSS 0.002
CVE-2023-40693
IBM Sterling B2B Integrator and IBM Sterling File Gateway Cross-Site Scripting
Published 2026-03-13 · Analyzed
5.4EPSS 0.002
CVE-2024-54183
IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting
Published 2025-06-18 · Analyzed
5.4EPSS 0.002
CVE-2025-2793
IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting
Published 2025-07-08 · Analyzed
5.4EPSS 0.002
CVE-2025-36135
IBM Sterling B2B Integrator and IBM Sterling File Gateway are Vulnerable to Cross-Site Scripting
Published 2025-11-07 · Analyzed
5.4EPSS 0.002
CVE-2025-36431
XSS Security Vulnerability in response header affects IBM Sterling B2B Integrator and IBM Sterling File Gateway
Published 2026-07-30 · Analyzed
5.4EPSS 0.002
CVE-2025-36298
Security Vulnerability in Ebics server affects IBM Sterling B2B Integrator and IBM Sterling File Gateway
Published 2026-07-30 · Analyzed
5.4EPSS 0.002
CVE-2019-4423
IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162769.
Published 2019-09-30 · Modified
5.3EPSS 0.027
CVE-2018-1398
IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote attacker to download certain files that could contain sensitive information. IBM X-Force ID: 138434.
Published 2018-07-20 · Modified
5.3EPSS 0.024
CVE-2021-39086
IBM Sterling File Gateway 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 215889.
Published 2022-08-16 · Modified
5.3EPSS 0.009
1 / 2Next →