CVE-2025-36348: The Dashboard of IBM Sterling B2B Integrator and IBM Sterling File Gateway is Vulnerable to Information Disclosure
IBM Sterling B2B Integrator and IBM Sterling File Gateway could allow a remote privileged attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
Other sources
IBM Sterling B2B Integrator versions 6.1.0.0 through 6.1.2.72, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1, and IBM Sterling File Gateway versions 6.1.0.0 through 6.1.2.72, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1 may expose sensitive information to a remote privileged attacker due to the application returning detailed technical error messages in the browser.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36348?
CVE-2025-36348 has been rated as a medium severity vulnerability due to the potential for information disclosure.
How do I fix CVE-2025-36348?
To fix CVE-2025-36348, apply the latest security patches provided by IBM for Sterling B2B Integrator and Sterling File Gateway.
Which versions are affected by CVE-2025-36348?
CVE-2025-36348 affects IBM Sterling B2B Integrator versions from 6.1.0.0 to 6.1.2.7_2 and 6.2.0.0 to 6.2.0.5, as well as 6.2.1.0 to 6.2.1.1, and IBM Sterling File Gateway in similar version ranges.
What type of vulnerability is CVE-2025-36348?
CVE-2025-36348 is categorized as an information disclosure vulnerability, allowing remote attackers to access sensitive information.
Who is impacted by CVE-2025-36348?
Organizations using IBM Sterling B2B Integrator and IBM Sterling File Gateway within the specified versions are impacted by CVE-2025-36348.