CVE-2025-36135: IBM Sterling B2B Integrator and IBM Sterling File Gateway are Vulnerable to Cross-Site Scripting
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.71, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.71, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Sterling B2B Integrator is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36135?
CVE-2025-36135 is classified as a high-severity vulnerability due to its potential impact on application security.
How do I fix CVE-2025-36135?
To fix CVE-2025-36135, you should upgrade to the latest version of IBM Sterling B2B Integrator or IBM Sterling File Gateway that addresses this vulnerability.
What types of attacks can exploit CVE-2025-36135?
CVE-2025-36135 can be exploited through cross-site scripting attacks, allowing attackers to inject malicious scripts.
Who is affected by CVE-2025-36135?
CVE-2025-36135 affects users of IBM Sterling B2B Integrator and IBM Sterling File Gateway versions between 6.0.0.0 and 6.2.1.0.
What are the potential consequences of CVE-2025-36135?
The potential consequences of CVE-2025-36135 include unauthorized access to user accounts and exposure of sensitive information due to successful script execution.