SB2026091410 - IBM Sterling B2B Integrator and IBM Sterling File Gateway update for Spring Security



SB2026091410 - IBM Sterling B2B Integrator and IBM Sterling File Gateway update for Spring Security

Published: September 14, 2026

Security Bulletin ID SB2026091410
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Configuration (CVE-ID: CVE-2026-22748)

CWE-ID: CWE-16 - Configuration

CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to modify application integrity checks.

The vulnerability exists due to improper security configuration in NimbusJwtDecoder#withIssuerLocation and NimbusReactiveJwtDecoder#withIssuerLocation when configuring JWT decoding without a separate OAuth2TokenValidator<Jwt>. A remote user can present a JWT with an unexpected issuer to modify application integrity checks.

The issue arises because issuer validation may be assumed to be enabled automatically when using withIssuerLocation.


Remediation

Install update from vendor's website.