CVE-2025-36368: IBM Sterling B2B Integrator and IBM Sterling File Gateway SQL Injection
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.72, 6.2.0.0 through 6.2.0.51, and 6.2.1.0 through 6.2.1.11 are vulnerable to SQL injection. An administrative user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Other sources
IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. An administrative user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36368?
CVE-2025-36368 is considered a critical vulnerability due to its potential for SQL injection that could lead to unauthorized access to sensitive data.
How do I fix CVE-2025-36368?
To fix CVE-2025-36368, upgrade IBM Sterling B2B Integrator and IBM Sterling File Gateway to the patched versions released by IBM.
What versions of software are affected by CVE-2025-36368?
CVE-2025-36368 affects IBM Sterling B2B Integrator and IBM Sterling File Gateway versions 6.1.0.0 to 6.1.2.7_2, 6.2.0.0 to 6.2.0.5_1, and 6.2.1.0 to 6.2.1.1_1.
Who can exploit CVE-2025-36368?
An administrative user could exploit CVE-2025-36368 by sending specially crafted SQL queries that manipulate database queries.
What are the potential impacts of CVE-2025-36368?
The potential impacts of CVE-2025-36368 include unauthorized data access, data leakage, and possible complete compromise of the affected systems.