CVE-2025-36431: XSS Security Vulnerability in response header affects IBM Sterling B2B Integrator and IBM Sterling File Gateway
IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.01 and IBM Sterling File Gateway 6.2.2.0 through 6.2.2.01 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Sterling File Gateway is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Sterling B2B Integrator and IBM Sterling File Gatewayto a version that resolves this vulnerability.Fixed in 6.2.2.1Patch IT49587 - Compensating control
Mitigate XSS impact by reducing risk from the XSS Security Vulnerability in response header affecting IBM Sterling B2B Integrator and IBM Sterling File Gateway (per the described XSS Security Vulnerability context).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36431?
The severity of CVE-2025-36431 is medium with a CVSS score of 5.4.
How do I fix CVE-2025-36431?
To fix CVE-2025-36431, update IBM Sterling B2B Integrator and IBM Sterling File Gateway to the latest version that addresses the vulnerability.
What applications are affected by CVE-2025-36431?
CVE-2025-36431 affects IBM Sterling B2B Integrator and IBM Sterling File Gateway versions 6.2.2.0 to 6.2.2.0_1.
What type of vulnerability is CVE-2025-36431?
CVE-2025-36431 is a cross-site scripting (XSS) vulnerability.
Who can exploit CVE-2025-36431?
An authenticated user can exploit CVE-2025-36431 to embed arbitrary JavaScript code in the Web UI.