Sceawere

Vulnerability Detail

CVE-2026-19273UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM B2B Integrator Authentication Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
2h ago
Vendor
IBM
Product
Sterling B2B Integrator
Attack Type
CWE-287 Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 Standard Edition could allow a remote authenticated attacker to bypass security restrictions due to improper authentication.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-09-14T21:17:04.490Z",
  "pubdate": "2026-09-14T21:17:04.490Z",
  "executiveSummary": "IBM Sterling B2B Integrator and IBM Sterling File Gateway are susceptible to an authentication bypass vulnerability stemming from improper authentication implementation.\nThis vulnerability allows a remote authenticated attacker to circumvent existing security restrictions within the application environment.\nThe flaw affects various versions within the 6.2.0.x, 6.2.1.x, and 6.2.2.x release branches.\nThe risk implication is significant as it undermines the integrity of the authorization layer, potentially allowing unauthorized access to protected resources or elevated operational capabilities.\nExploitation requires the attacker to have an existing authenticated session or access credentials, though the specific mechanism allows for the bypass of intended access control logic.\nSuccessful exploitation could result in unauthorized data access or unauthorized execution of administrative functions, depending on the scope of the bypassed security controls.",
  "technicalDetails": "The vulnerability resides within the authentication framework of IBM Sterling B2B Integrator and IBM Sterling File Gateway. The root cause is categorized as an improper authentication implementation, where the application logic fails to consistently validate the security context or session integrity of an authenticated user.\nIn a standard deployment, the application relies on specific authentication modules to verify user identities and enforce granular access control lists (ACLs). Due to a failure in the validation routine, an attacker who has successfully authenticated to the system can manipulate request parameters or session tokens to access functions or data segments that are otherwise restricted to higher-privileged roles or restricted service endpoints.\nThe attack flow typically involves an actor with low-privilege access identifying a target endpoint or function that performs secondary security checks. By injecting crafted headers, manipulating API calls, or exploiting discrepancies between the session state and the authorization server's view of the user’s privileges, the attacker bypasses the secondary authentication or authorization validation.\nThis indicates that the vulnerable component does not adequately enforce secure authorization checks post-initial authentication. Because the system assumes that once a user is authenticated, their subsequent requests are implicitly trusted or improperly checked against the required security constraints for specific operations, the attacker can traverse paths or execute commands that should be explicitly denied.\nAffected versions include IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 through 6.2.1.2, and 6.2.2.0 through 6.2.2.1 Standard Edition. Since the vulnerability is accessible to remote authenticated attackers, it poses a risk to any network-exposed instance of the software.\nPost-exploitation impact involves the potential for horizontal or vertical privilege escalation, where the attacker may interact with system files, configuration settings, or process management components. The integrity of the business integration processes can be compromised, potentially allowing for the unauthorized manipulation of file transfers or business document payloads if the attacker successfully targets the File Gateway components."
}
CVE-2026-19273: IBM B2B Integrator Authentication Bypass (MEDIUM Severity, CVSS: 5.4) | Sceawere