Multiple vulnerabilities were addressed in IBM Sterling Connect:Express for UNIX.
Published Jan 20, 2026
6.5
MEDIUMCVSS 3.1
EPSS 0.18%
Description
IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system.
Affected products
- Vendor IBM Product Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 Defaultunknown
Affected
- ≥ 5.2.0.00, ≤ 5.2.0.12
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| IBM | Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 | unknown | Affected
|
- ≥ 5.2.0.00 · < 5.2.0.13
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Affected Product(s)Fixed in releaseInstructionsSterling Connect:Express Adapter for Sterling B2B Integrator 5.2.05.2.0.13 IBM Support: Fix Central - Select fixes https://www.ibm.com/support/fixcentral/swg/selectFixes
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-3367 Advisory
- https://www.ibm.com/support/pages/node/7257244 vendor-advisorypatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-3367 | Advisory | |
| https://www.ibm.com/support/pages/node/7257244 | vendor-advisorypatchVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data