CVE-2026-7775: Cross-site Scripting Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.12, and 6.2.2.0 through 6.2.2.01 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.12, and 6.2.2.0 through 6.2.2.01 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Sterling B2B Integrator and IBM Sterling File Gateway is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Sterling B2B Integrator and IBM Sterling File Gatewayto a version that resolves this vulnerability.Fixed in 6.2.0.6_1Patch IT49357 - Upgrade
Upgrade
IBM Sterling B2B Integrator and IBM Sterling File Gatewayto a version that resolves this vulnerability.Fixed in 6.2.1.2Patch IT49357 - Upgrade
Upgrade
IBM Sterling B2B Integrator and IBM Sterling File Gatewayto a version that resolves this vulnerability.Fixed in 6.2.2.1Patch IT49357
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7775?
CVE-2026-7775 has a medium severity rating of 5.5.
How do I fix CVE-2026-7775?
To fix CVE-2026-7775, update your IBM Sterling B2B Integrator or IBM Sterling File Gateway to the latest patched version.
What types of systems are affected by CVE-2026-7775?
CVE-2026-7775 affects IBM Sterling B2B Integrator versions 6.2.0.0 through 6.2.2.0_1 and IBM Sterling File Gateway versions 6.2.0.0 through 6.2.2.0_1.
What type of vulnerability is CVE-2026-7775?
CVE-2026-7775 is classified as a stored cross-site scripting (XSS) vulnerability.
What can attackers do with CVE-2026-7775?
Exploiting CVE-2026-7775 allows attackers to execute malicious scripts in the context of a user's session.