← Browse

CVE-2026-7253

Low

No strong exploitation signal.

CVSS base
6.0 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L
EPSS — probability of exploitation (30 days)
0.4%
31.0th percentile
CISA KEV
Not listed
Weakness / dates
CWE-89
Published 2026-06-22 · modified 2026-07-23

CVSS breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L

Attack VectorNNetwork
Attack ComplexityLLow
Privileges RequiredHHigh
User InteractionNNone
ScopeUUnchanged
ConfidentialityHHigh
IntegrityLLow
AvailabilityLLow

Timeline

Description

IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

Affected

ibm

References

Official: NVD · CVE.org