CVE-2025-36066: Multiple vulnerabilities were addressed in IBM Sterling Connect:Express for UNIX.
IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36066?
CVE-2025-36066 has been assigned a medium severity rating due to its potential for cross-site scripting vulnerabilities.
How do I fix CVE-2025-36066?
To fix CVE-2025-36066, update your IBM Sterling Connect:Express Adapter for Sterling B2B Integrator to version 5.2.0.13 or later.
What versions are affected by CVE-2025-36066?
CVE-2025-36066 affects IBM Sterling Connect:Express Adapter for Sterling B2B Integrator versions 5.2.0.00 through 5.2.0.12.
Who can exploit CVE-2025-36066?
CVE-2025-36066 can be exploited by unauthenticated attackers to execute arbitrary JavaScript.
What type of vulnerability is CVE-2025-36066?
CVE-2025-36066 is categorized as a cross-site scripting (XSS) vulnerability.