CVE-2025-36298: Security Vulnerability in Ebics server affects IBM Sterling B2B Integrator and IBM Sterling File Gateway
IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.72, 6.2.0.0 through 6.2.0.52, 6.2.1.0 through 6.2.1.12, and 6.2.2.0 through 6.2.2.01 and IBM Sterling File Gateway 6.1.2.0 through 6.1.2.72, 6.2.0.0 through 6.2.0.52, 6.2.1.0 through 6.2.1.12, and 6.2.2.0 through 6.2.2.01 Ebics server component is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Sterling B2B Integrator and IBM Sterling File Gateway Ebics server component is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Sterling B2B Integrator (Ebics server) / IBM Sterling File Gateway (Ebics server)to a version that resolves this vulnerability.Fixed in 6.1.2.8Patch IT48302 - Upgrade
Upgrade
IBM Sterling B2B Integrator (Ebics server) / IBM Sterling File Gateway (Ebics server)to a version that resolves this vulnerability.Fixed in 6.2.0.6Patch IT48302 - Upgrade
Upgrade
IBM Sterling B2B Integrator (Ebics server) / IBM Sterling File Gateway (Ebics server)to a version that resolves this vulnerability.Fixed in 6.2.1.2Patch IT48302 - Upgrade
Upgrade
IBM Sterling B2B Integrator (Ebics server) / IBM Sterling File Gateway (Ebics server)to a version that resolves this vulnerability.Fixed in 6.2.2.1Patch IT48302
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36298?
CVE-2025-36298 has a medium severity score of 5.4.
How do I fix CVE-2025-36298?
To fix CVE-2025-36298, apply the latest security patches provided by IBM for the affected versions of IBM Sterling B2B Integrator and IBM Sterling File Gateway.
Which software versions are affected by CVE-2025-36298?
CVE-2025-36298 affects IBM Sterling B2B Integrator versions 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1, as well as IBM Sterling File Gateway versions 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1.
What type of vulnerability is CVE-2025-36298?
CVE-2025-36298 is categorized as a Cross-Site Scripting (XSS) vulnerability.
Is there an exploit available for CVE-2025-36298?
As of now, there is no publicly available exploit for CVE-2025-36298.