CVE-2026-7253: IBM Sterling File Gateway SQL Injection
IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Sterling B2B Integratorto a version that resolves this vulnerability.Fixed in 6.2.1.2Patch APAR - Upgrade
Upgrade
IBM Sterling B2B Integratorto a version that resolves this vulnerability.Fixed in 6.2.2.1Patch APAR - Upgrade
Upgrade
IBM Sterling File Gatewayto a version that resolves this vulnerability.Fixed in 6.2.1.2Patch IT49319 - Upgrade
Upgrade
IBM Sterling File Gatewayto a version that resolves this vulnerability.Fixed in 6.2.2.1Patch IT49319
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7253?
The severity of CVE-2026-7253 is rated as medium with a base score of 5.3.
What type of vulnerability is identified in CVE-2026-7253?
CVE-2026-7253 identifies a Server-Side Request Forgery (SSRF) vulnerability.
Who is affected by CVE-2026-7253?
CVE-2026-7253 affects users of IBM Watson Speech Services Cartridge and IBM Sterling File Gateway.
How can I mitigate the risk posed by CVE-2026-7253?
To mitigate CVE-2026-7253, ensure that access controls are enforced to limit unauthorized requests.
Can CVE-2026-7253 lead to data exposure?
Yes, CVE-2026-7253 may allow an attacker to conduct network enumeration, which could lead to data exposure.