CVE-2025-36113: Multiple vulnerabilities were addressed in IBM Sterling Connect:Express for UNIX.
IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Sterling Connect:Express for UNIX is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36113?
CVE-2025-36113 is classified as a high severity vulnerability due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2025-36113?
To fix CVE-2025-36113, you should upgrade the IBM Sterling Connect:Express Adapter for Sterling B2B Integrator to a version later than 5.2.0.12.
Who is affected by CVE-2025-36113?
CVE-2025-36113 affects users of IBM Sterling Connect:Express Adapter for Sterling B2B Integrator versions 5.2.0.00 through 5.2.0.12.
What types of attacks can CVE-2025-36113 facilitate?
CVE-2025-36113 can facilitate cross-site scripting attacks, allowing attackers to execute arbitrary JavaScript in the context of authenticated users.
Are there any configurations that can mitigate CVE-2025-36113?
While upgrading is the primary fix for CVE-2025-36113, limiting user permissions and input validation can help mitigate the risk.