CVE-2026-7253

Summary

IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

Affected Software

VendorProductVersion RangeStatus
IBMSterling B2B Integrator6.2.1.0 <= 6.2.1.1_2affected
IBMSterling B2B Integrator6.2.2.0 <= 6.2.2.0_1affected
IBMSterling File Gateway6.2.1.0 <= 6.2.1.1_2affected
IBMSterling File Gateway6.2.2.0 <= 6.2.2.0_1affected

Weaknesses

  • CWE-89: CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References