CVE-2026-0835: XSS
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.72, 6.2.0.0 through 6.2.0.51, 6.2.1.0 through 6.2.1.11, and 6.2.2.0 are vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Sterling B2B Integrator and IBM Sterling File Gateway is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0835?
CVE-2026-0835 is classified as a medium severity vulnerability due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2026-0835?
To fix CVE-2026-0835, upgrade IBM Sterling B2B Integrator and IBM Sterling File Gateway to the latest patched version provided by IBM.
What products are affected by CVE-2026-0835?
CVE-2026-0835 affects IBM Sterling B2B Integrator and IBM Sterling File Gateway versions from 6.1.0.0 to 6.2.2.0.
What type of attack can CVE-2026-0835 facilitate?
CVE-2026-0835 can facilitate cross-site scripting attacks, allowing attackers to execute arbitrary JavaScript code within the web UI.
Who is vulnerable to CVE-2026-0835?
Authenticated users of affected versions of IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to CVE-2026-0835.