CVE-2026-3158: Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway due to information disclosure
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.52, 6.2.1.0 through 6.2.1.12, and 6.2.2.0 through 6.2.2.01 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.52, 6.2.1.0 through 6.2.1.12, and 6.2.2.0 through 6.2.2.01 is vulnerable to an information disclosure due to sensitive information being included in the source code comments of a dashboard component.
Other sources
IBM Sterling B2B Integrator and IBM Sterling File Gateway is vulnerable to an information disclosure due to sensitive information being included in the source code comments of a dashboard component.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Sterling B2B Integrator / IBM Sterling File Gatewayto a version that resolves this vulnerability.Fixed in 6.2.0.6Patch IT49080 - Upgrade
Upgrade
IBM Sterling B2B Integrator / IBM Sterling File Gatewayto a version that resolves this vulnerability.Fixed in 6.2.1.2Patch IT49080 - Upgrade
Upgrade
IBM Sterling B2B Integrator / IBM Sterling File Gatewayto a version that resolves this vulnerability.Fixed in 6.2.2.1Patch IT49080
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3158?
CVE-2026-3158 has a medium severity rating of 4.3.
How do I fix CVE-2026-3158?
To mitigate CVE-2026-3158, upgrade IBM Sterling B2B Integrator and IBM Sterling File Gateway to the latest versions provided by IBM.
What versions are affected by CVE-2026-3158?
CVE-2026-3158 affects IBM Sterling B2B Integrator versions 6.2.0.0 to 6.2.2.0_1 and IBM Sterling File Gateway versions 6.2.0.0 to 6.2.2.0_1.
What type of vulnerability is CVE-2026-3158?
CVE-2026-3158 is an information disclosure vulnerability.
What kind of sensitive information is impacted by CVE-2026-3158?
CVE-2026-3158 potentially exposes sensitive information due to improper handling within the affected IBM software.