SB2026072409 - IBM Sterling B2B Integrator and IBM Sterling File Gateway update for Spring Security Servlet



SB2026072409 - IBM Sterling B2B Integrator and IBM Sterling File Gateway update for Spring Security Servlet

Published: July 24, 2026

Security Bulletin ID SB2026072409
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Protection Mechanism Failure (CVE-ID: CVE-2026-22732)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper security header handling in HTTP response header writing for servlet applications when using lazy writing of HTTP headers. A remote attacker can trigger application responses where the configured security headers are not written to disclose sensitive information.

This issue affects servlet applications that specify HTTP response headers using Spring Security with lazy header writing enabled.


Remediation

Install update from vendor's website.