SB2026091410 - IBM Sterling B2B Integrator and IBM Sterling File Gateway update for Spring Security
Published: September 14, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Configuration (CVE-ID: CVE-2026-22748)
CWE-ID: CWE-16 - Configuration
CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to modify application integrity checks.
The vulnerability exists due to improper security configuration in NimbusJwtDecoder#withIssuerLocation and NimbusReactiveJwtDecoder#withIssuerLocation when configuring JWT decoding without a separate OAuth2TokenValidator<Jwt>. A remote user can present a JWT with an unexpected issuer to modify application integrity checks.
The issue arises because issuer validation may be assumed to be enabled automatically when using withIssuerLocation.
Remediation
Install update from vendor's website.