CVE-2026-7769

IBM · Sterling B2B Integrator

IBM Sterling B2B Integrator and Sterling File Gateway are affected by an SQL injection vulnerability, potentially allowing authenticated attackers to access sensitive data.

Executive summary

An SQL injection vulnerability in IBM Sterling B2B Integrator and Sterling File Gateway allows authenticated users to potentially compromise system integrity and data confidentiality.

Vulnerability

The software improperly neutralizes special elements used in SQL commands, which allows an authenticated attacker to inject malicious SQL queries. This flaw can lead to the unauthorized disclosure or manipulation of database information.

Business impact

The CVSS score of 8.1 reflects the high impact of this vulnerability on data confidentiality and integrity. Successful exploitation could allow an attacker to exfiltrate sensitive business files or modify transaction data, which would have severe consequences for business operations and regulatory compliance.

Remediation

Immediate Action: Apply the relevant security update (B2Bi 6.2.0.6, 6.2.1.2, or 6.2.2.1 depending on the current version) as detailed in the IBM support documentation.

Proactive Monitoring: Monitor database query logs for suspicious patterns or syntax that indicate injection attempts, especially from internal users.

Compensating Controls: Utilize database-level security controls to restrict the application user's permissions to the minimum necessary for normal operations.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the severity of SQL injection, organizations should prioritize the deployment of the provided IBM patches to their B2B Integrator and File Gateway environments. Ensuring that all systems are updated to the specified versions is critical to preventing unauthorized database access.