CVE-2026-7253 Details
Description
IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
A Server-Side Request Forgery (SSRF) vulnerability has been identified in the IBM Watson Speech Services Cartridge, specifically within the Sterling File Gateway component. This vulnerability allows authenticated attackers to send unauthorized requests from the system, which could lead to network enumeration or facilitate other types of attacks. The affected versions of the IBM Watson Speech Services Cartridge range from 4.0.0 to 5.3.1.
Users can upgrade to IBM Watson Speech Services Cartridge version 5.4 or version 5.3.1 Patch 7. Version 5.4 is available for download from the IBM Cloud Pak for Data documentation site. Version 5.3.1 Patch 7 can also be downloaded from the same site.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7280923 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm watson speech services cartridge | >= 4.0.0, < 5.3.1 5.3.1 - |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Modified | [email protected] |
| Jul 22, 2026 | CVE Modified | [email protected] |
| Jul 22, 2026 | CVE Modified | [email protected] |
| Jun 30, 2026 | Initial Analysis | [email protected] |
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 22, 2026 | New CVE Received | [email protected] |