CVE-2026-3158
Awaiting Analysis Awaiting Analysis - Queue

Information Disclosure in IBM Sterling B2B Integrator

Vulnerability report for CVE-2026-3158, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-28

Last updated on: 2026-07-28

Assigner: IBM Corporation

Description

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to an information disclosure due to sensitive information being included in the source code comments of a dashboard component.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-28
Last Modified
2026-07-28
Generated
2026-07-29
AI Q&A
2026-07-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
ibm sterling_b2b_integrator From 6.2.0.0 (inc) to 6.2.0.5_2 (inc)
ibm sterling_b2b_integrator From 6.2.1.0 (inc) to 6.2.1.1_2 (inc)
ibm sterling_b2b_integrator From 6.2.2.0 (inc) to 6.2.2.0_1 (inc)
ibm sterling_file_gateway From 6.2.0.0 (inc) to 6.2.0.5_2 (inc)
ibm sterling_file_gateway From 6.2.1.0 (inc) to 6.2.1.1_2 (inc)
ibm sterling_file_gateway From 6.2.2.0 (inc) to 6.2.2.0_1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-615 While adding general comments is very useful, some programmers tend to leave important data, such as: filenames related to the web application, old links or links which were not meant to be browsed by users, old code fragments, etc.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM Sterling B2B Integrator and IBM Sterling File Gateway versions 6.2.0.0 through 6.2.2.0_1 have an information disclosure vulnerability. Sensitive data is exposed in source code comments of a dashboard component. This flaw is tracked under CWE-615, which involves sensitive information in comments.

Detection Guidance

This vulnerability involves sensitive information in source code comments of a dashboard component in IBM Sterling B2B Integrator and File Gateway. Detection requires inspecting source code files for comments containing sensitive data. Review files in the dashboard component directories for hardcoded credentials, API keys, or internal paths. Use code search tools like grep to scan for patterns like 'password=', 'api_key=', or 'secret=' in comments.

Impact Analysis

An attacker with access to the source code could view sensitive information in comments, potentially leading to unauthorized data access or further exploitation. The impact is limited as it requires some access level (PR:L) and has low severity (CVSS 4.3).

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA if sensitive data like personal or health information is exposed in comments. Organizations must ensure no sensitive data is present in source code to meet regulatory requirements.

Mitigation Strategies
  • Upgrade to fixed versions: Apply IBM's remediation fixes for versions 6.2.0.6, 6.2.1.2, or 6.2.2.1 available via Fix Central or IBM Entitled Registry.
  • Review source code: Inspect dashboard component files for sensitive information in comments and remove or redact any exposed data.
  • Monitor for misuse: Check logs for unauthorized access attempts or unusual activity related to the dashboard component.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-3158. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart