目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-7362— IBM Sterling B2B Integrator权限许可和访问控制问题漏洞

CVSS 4.3 · Medium EPSS 0.16% · P6

Possible ATT&CK Techniques 1AI

T1530 · Data from Cloud Storage

Affected Version Matrix 4

ベンダープロダクトVersion Rangeステータス
IBMSterling B2B Integrator6.2.1.0≤ 6.2.1.1_2affected
6.2.2.0≤ 6.2.2.0_1affected
IBMSterling File Gateway6.2.1.0≤ 6.2.1.1_2affected
6.2.2.0≤ 6.2.2.0_1affected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-7362の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Improper Access Control Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway
ソース: CVE Program / CVE List V5
脆弱性説明
IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 could allow an authenticated user to obtain sensitive information that should only be available to a privileged user.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
ソース: CVE Program / CVE List V5
脆弱性タイプ
访问控制不恰当
ソース: CVE Program / CVE List V5
脆弱性タイトル
IBM Sterling B2B Integrator权限许可和访问控制问题漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
IBM sterling b2b integrator是美国IBM公司的一个B2B集成平台。 IBM Sterling B2B Integrator存在权限许可和访问控制问题漏洞,该漏洞源于访问控制不当,可能导致认证用户获取应仅对特权用户可用的敏感信息。以下版本受到影响:IBM Sterling B2B Integrator 6.2.1.0版本至6.2.1.1_2版本和6.2.2.0版本至6.2.2.0_1版本。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
IBMSterling B2B Integrator 6.2.1.0 ~ 6.2.1.1_2 cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.1.0:*:*:*:*:*:*:*
IBMSterling File Gateway 6.2.1.0 ~ 6.2.1.1_2 cpe:2.3:a:ibm:sterling_file_gateway:6.2.1.0:*:*:*:*:*:*:*

II. CVE-2026-7362の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-7362のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-7362 厂商安全公告 (1)

Same Patch Batch · IBM · 2026-07-28 · 31 CVEs total

CVE-2026-144469.8 CRITICALIBM WebSphere Application Server is affected by a privilege escalation
CVE-2026-145129.8 CRITICALIBM WebSphere Application Server is affected by an unsafe deserialization and exposure of
CVE-2026-149739.3 CRITICALPath Traversal in IBM Desktop App
CVE-2026-149589.1 CRITICALOS command injection in IBM Aspera Faspex
CVE-2026-149599.1 CRITICALOS Command Injection in IBM Aspera Faspex
CVE-2026-150648.7 HIGHIBM WebSphere Application Server and WebSphere Application Server Liberty are affected by
CVE-2026-153258.7 HIGHIBM WebSphere Application Server and WebSphere Application Server Liberty are affected by
CVE-2026-149968.2 HIGHMultiple vulnerabilities in IBM Aspera Faspex
CVE-2026-77698.1 HIGHSQL injection Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File
CVE-2026-149748.1 HIGHIBM WebSphere Application Server is affected by cross-site scripting and deserialization v
CVE-2026-149817.5 HIGHIBM WebSphere Application Server and WebSphere Application Server Liberty are affected by
CVE-2026-150577.5 HIGHIBM WebSphere Application Server Liberty is affected by a denial of service vulnerability
CVE-2026-152807.5 HIGHIBM WebSphere Application Server Liberty is affected by a remote code execution and path-s
CVE-2026-134637.5 HIGHDue to use of IBM Storage Protect, IBM Cloud Pak System is affected by vulnerability []
CVE-2026-153287.4 HIGHIBM WebSphere Application Server and WebSphere Application Server Liberty is inconsistent
CVE-2026-145287.4 HIGHIBM WebSphere Application Server is affected by an unsafe deserialization and exposure of
CVE-2026-148937.3 HIGHIBM Instana Observability is affected by multiple Prototype Pollution within Instana Agent
CVE-2026-134427.1 HIGHLangflow is affected by NET Misconfiguration: Use of Impersonation due to multiple unauthe
CVE-2026-149767.1 HIGHIBM WebSphere Application Server Liberty is affected by a remote code execution and path-s
CVE-2026-161927.1 HIGHIBM WebSphere Application Server Liberty is affected by a denial of service

Showing 20 of 31 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-7362へのコメント

まだコメントはありません


コメントを残す