CVE-2025-36065: Multiple vulnerabilities were addressed in IBM Sterling Connect:Express for UNIX.
IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system.
Other sources
IBM Sterling Connect:Express for UNIX does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36065?
CVE-2025-36065 is considered a critical vulnerability due to the risk of session impersonation.
How do I fix CVE-2025-36065?
To fix CVE-2025-36065, upgrade your IBM Sterling Connect:Express Adapter for Sterling B2B Integrator to a version above 5.2.0.12.
What vulnerabilities are associated with CVE-2025-36065?
CVE-2025-36065 addresses the issue of session management that fails to invalidate sessions after a browser closure.
Who is affected by CVE-2025-36065?
Users of IBM Sterling Connect:Express Adapter for Sterling B2B Integrator versions 5.2.0.00 through 5.2.0.12 are affected by CVE-2025-36065.
What impact does CVE-2025-36065 have on users?
CVE-2025-36065 may allow an authenticated user to impersonate another user, compromising user security.