Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-7253

Опубликовано: 22 июн. 2026
Источник: nvd
CVSS3: 6
CVSS3: 8.8
EPSS Низкий

Описание

IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ibm:watson_speech_services_cartridge:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 5.3.1 (исключая)
cpe:2.3:a:ibm:watson_speech_services_cartridge:5.3.1:-:*:*:*:*:*:*

EPSS

Процентиль: 11%
0.00206
Низкий

6 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 5.3
github
около 1 месяца назад

IBM Watson Speech Services Cartridge is vulnerable to Server-Side Request Forgery (SSRF) in Sterling File Gateway, due to a flaw which may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks [GHSA-rr7j-v2q5-chgv] [CVE-2026-7253]. IBM Sterling File Gateway is used in our speech runtimes. This vulnerabilitiy has been addressed. Please read the details for remediation below.

EPSS

Процентиль: 11%
0.00206
Низкий

6 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-89