CVE-2026-1918: IBM Sterling B2B Integrator and IBM Sterling File Gateway store sensitive information in a log file
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.52, 6.2.1.0 through 6.2.1.12, and 6.2.2.0 through 6.2.2.01 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.52, 6.2.1.0 through 6.2.1.12, and 6.2.2.0 through 6.2.2.01 stores potentially sensitive information in log files that could be read by a privileged user.
Other sources
IBM Sterling B2B Integrator and IBM Sterling File Gateway stores potentially sensitive information in log files that could be read by a privileged user.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Sterling B2B Integrator and IBM Sterling File Gatewayto a version that resolves this vulnerability.Fixed in 6.2.0.6Patch IT49028 - Upgrade
Upgrade
IBM Sterling B2B Integrator and IBM Sterling File Gatewayto a version that resolves this vulnerability.Fixed in 6.2.1.2Patch IT49028 - Upgrade
Upgrade
IBM Sterling B2B Integrator and IBM Sterling File Gatewayto a version that resolves this vulnerability.Fixed in 6.2.2.1Patch IT49028
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1918?
The severity of CVE-2026-1918 is medium, rated at 4.9.
How do I fix CVE-2026-1918?
To fix CVE-2026-1918, update IBM Sterling B2B Integrator or IBM Sterling File Gateway to a version that is not affected by this vulnerability.
What information is stored in log files for CVE-2026-1918?
CVE-2026-1918 may allow the storage of potentially sensitive information in log files that could be accessed by unauthorized users.
Which versions of IBM Sterling B2B Integrator are affected by CVE-2026-1918?
IBM Sterling B2B Integrator versions 6.2.0.0 to 6.2.0.5_2, 6.2.1.0 to 6.2.1.1_2, and 6.2.2.0 to 6.2.2.0_1 are affected by CVE-2026-1918.
What is the impact of CVE-2026-1918?
The impact of CVE-2026-1918 is that sensitive data can be exposed through log files, potentially leading to unauthorized access.