Stored Cross-Site Scripting Vulnerability in IBM Sterling Products
CVE-2026-7775

5.5MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
28 July 2026

What is CVE-2026-7775?

The vulnerability found in certain versions of IBM Sterling B2B Integrator and File Gateway enables a privileged user to insert malicious JavaScript code into the Web UI. This can compromise user sessions and potentially lead to unauthorized disclosure of sensitive information, affecting the integrity of web application interactions.

Affected Version(s)

Sterling B2B Integrator 6.2.0.0 <= 6.2.0.6

Sterling B2B Integrator 6.2.1.0 <= 6.2.1.1_2

Sterling B2B Integrator 6.2.2.0 <= 6.2.2.0_1

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.