CVE-2025-36063: Multiple vulnerabilities were addressed in IBM Sterling Connect:Express for UNIX.
IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.
Other sources
IBM Sterling Connect:Express for UNIX does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36063?
CVE-2025-36063 has been classified as a medium severity vulnerability.
How do I fix CVE-2025-36063?
To fix CVE-2025-36063, update your IBM Sterling Connect:Express Adapter for Sterling B2B Integrator to version 5.2.0.13 or higher.
What are the risks associated with CVE-2025-36063?
The risk associated with CVE-2025-36063 is that an authenticated user may impersonate another user due to improper session management.
Who is affected by CVE-2025-36063?
Users of IBM Sterling Connect:Express Adapter for Sterling B2B Integrator versions 5.2.0.00 through 5.2.0.12 are affected by CVE-2025-36063.
Is CVE-2025-36063 exploitable remotely?
CVE-2025-36063 is not directly exploitable remotely as it requires authenticated user access to the system.