IBM Sterling B2B/FTP Integrator 6.2.0.0-6.2.2.0_1 Info Leak (src comments)
CVE-2026-3158 Published on July 28, 2026

Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway due to information disclosure
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to an information disclosure due to sensitive information being included in the source code comments of a dashboard component.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-3158 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a small impact on integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
LOW
Integrity Impact:
NONE
Availability Impact:
NONE

Weakness Type

Inclusion of Sensitive Information in Source Code Comments

While adding general comments is very useful, some programmers tend to leave important data, such as: filenames related to the web application, old links or links which were not meant to be browsed by users, old code fragments, etc. An attacker who finds these comments can map the application's structure and files, expose hidden parts of the site, and study the fragments of code to reverse engineer the application, which may help develop further attacks against the site.


Products Associated with CVE-2026-3158

stack.watch emails you whenever new vulnerabilities are published in IBM Sterling B2b Integrator or IBM Sterling File Gateway. Just hit a watch button to start following.

 
 

Affected Versions

IBM Sterling B2B Integrator: IBM Sterling File Gateway: