Sceawere
Vulnerability Detail
CVE-2026-19290UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
IBM Sterling File Gateway Information Disclosure
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 2h ago
- Vendor
- IBM
- Product
- Sterling File Gateway
- Attack Type
- CWE-284 Improper Access Control
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 could allow a remote attacker to obtain sensitive information due to improper access control.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-09-14T21:17:04.767Z",
"pubdate": "2026-09-14T21:17:04.767Z",
"executiveSummary": "A critical security vulnerability has been identified in IBM Sterling File Gateway versions 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 through 6.2.1.2, and 6.2.2.0 through 6.2.2.1.\nThe vulnerability stems from improper access control mechanisms within the application.\nThis flaw enables a remote, unauthenticated or unauthorized attacker to gain illicit access to sensitive information that should otherwise be restricted.\nThe risk implication is significant as it potentially compromises the confidentiality of data transmitted or stored within the file gateway ecosystem.\nSuccessful exploitation allows attackers to harvest sensitive data by bypassing existing access control policies.\nOrganizations utilizing affected versions of IBM Sterling File Gateway are exposed to potential data breaches and unauthorized information exposure.",
"technicalDetails": "The vulnerability is rooted in an improper access control flaw within the IBM Sterling File Gateway architecture. This issue occurs when the application fails to adequately validate the authorization context of a user or system process before fulfilling requests for sensitive data resources.\nBy manipulating the request parameters or bypassing established security checks, a remote attacker can interact with internal application functions that handle sensitive business logic or data retrieval tasks.\nThe attack flow typically involves the attacker identifying specific endpoints or resources within the Sterling File Gateway environment that lack robust authorization enforcement. Upon identifying such an entry point, the attacker sends crafted requests designed to solicit responses containing sensitive information that would normally be shielded by access control constraints.\nSince the vulnerability pertains to improper access control, the system fails to verify whether the requester possesses the appropriate privileges to access the targeted object, file, or metadata. Consequently, the application processes the request as if it originated from an authorized entity, leading to the unauthorized disclosure of information.\nThe exploitation does not necessarily require complex payload injection; rather, it exploits the logic gap in the access control layer. The impact post-exploitation is characterized by the leakage of sensitive internal data, configuration details, or potentially proprietary file transmission data stored within the IBM Sterling File Gateway environment.\nAffected versions include 6.2.0.0-6.2.0.6_1, 6.2.1.0-6.2.1.2, and 6.2.2.0-6.2.2.1. The vulnerability is network-accessible, meaning that if the administrative or file transfer interfaces are reachable over a network, an attacker can attempt exploitation remotely. The severity is magnified by the potential for automated harvesting of data if the affected endpoints are discoverable through scanning or reconnaissance techniques. The lack of stringent access control checks serves as the primary technical vector enabling the bypass, effectively allowing unauthorized read access to internal resources."
}