CVE-2025-36115: Multiple vulnerabilities were addressed in IBM Sterling Connect:Express for UNIX.
IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0.00 through 5.2.0.12 does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system.
Other sources
IBM Sterling Connect:Express for UNIX does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36115?
CVE-2025-36115 has a high severity rating due to the potential for user impersonation.
How do I fix CVE-2025-36115?
To fix CVE-2025-36115, upgrade IBM Sterling Connect:Express Adapter for Sterling B2B Integrator to version 5.2.0.13 or later.
What systems are affected by CVE-2025-36115?
CVE-2025-36115 affects IBM Sterling Connect:Express Adapter for Sterling B2B Integrator versions 5.2.0.00 through 5.2.0.12.
What risks are associated with CVE-2025-36115?
CVE-2025-36115 poses a risk of authenticated users being able to impersonate other users on the system.
Is there a workaround for CVE-2025-36115 until a fix is applied?
Currently, there are no recommended workarounds for CVE-2025-36115, and updating is advised.