{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-36298", "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "state": "PUBLISHED", "assignerShortName": "ibm", "dateReserved": "2025-04-15T21:16:48.650Z", "datePublished": "2026-07-30T14:21:48.973Z", "dateUpdated": "2026-07-31T22:54:44.854Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "shortName": "ibm", "dateUpdated": "2026-07-30T14:21:48.973Z" }, "title": "Security Vulnerability in Ebics server affects IBM Sterling B2B Integrator and IBM Sterling File Gateway", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-79", "description": "CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')", "type": "CWE" } ] } ], "affected": [ { "vendor": "IBM", "product": "Sterling B2B Integrator", "versions": [ { "status": "affected", "version": "6.1.2.0", "lessThanOrEqual": "6.1.2.7_2", "versionType": "semver" }, { "status": "affected", "version": "6.2.0.0", "lessThanOrEqual": "6.2.0.5_2", "versionType": "semver" }, { "status": "affected", "version": "6.2.1.0", "lessThanOrEqual": "6.2.1.1_2", "versionType": "semver" }, { "status": "affected", "version": "6.2.2.0", "lessThanOrEqual": "6.2.2.0_1", "versionType": "semver" } ], "cpes": [ "cpe:2.3:a:ibm:sterling_b2b_integrator:6.1.2.0:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:sterling_b2b_integrator:6.1.2.7_2:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.0.0:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.0.5_2:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.1.0:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.1.1_2:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.2.0:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.2.0_1:*:*:*:*:*:*:*" ] }, { "vendor": "IBM", "product": "Sterling File Gateway", "versions": [ { "status": "affected", "version": "6.1.2.0", "lessThanOrEqual": "6.1.2.7_2", "versionType": "semver" }, { "status": "affected", "version": "6.2.0.0", "lessThanOrEqual": "6.2.0.5_2", "versionType": "semver" }, { "status": "affected", "version": "6.2.1.0", "lessThanOrEqual": "6.2.1.1_2", "versionType": "semver" }, { "status": "affected", "version": "6.2.2.0", "lessThanOrEqual": "6.2.2.0_1", "versionType": "semver" } ], "cpes": [ "cpe:2.3:a:ibm:sterling_file_gateway:6.1.2.0:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:sterling_file_gateway:6.1.2.7_2:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:sterling_file_gateway:6.2.0.0:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:sterling_file_gateway:6.2.0.5_2:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:sterling_file_gateway:6.2.1.0:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:sterling_file_gateway:6.2.1.1_2:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:sterling_file_gateway:6.2.2.0:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:sterling_file_gateway:6.2.2.0_1:*:*:*:*:*:*:*" ] } ], "descriptions": [ { "lang": "en", "value": "IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 Ebics server component is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "

IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 Ebics server component is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

" } ] } ], "references": [ { "url": "https://www.ibm.com/support/pages/node/7280668", "tags": [ "vendor-advisory", "patch" ] } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV3_1": { "version": "3.1", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE", "baseSeverity": "MEDIUM", "baseScore": 5.4, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } } ], "solutions": [ { "lang": "en", "value": "ProductVersionAPARRemediation & FixIBM Sterling B2B Integrator and IBM Sterling File Gateway6.1.2.0 - 6.1.2.7_2 IT48302 Apply B2Bi 6.1.2.8, 6.2.0.6, 6.2.1.2, 6.2.2.1IBM Sterling B2B Integrator and IBM Sterling File Gateway6.2.0.0 - 6.2.0.5_2 IT48302   Apply B2Bi 6.2.0.6, 6.2.1.2, 6.2.2.1IBM Sterling B2B Integrator and IBM Sterling File Gateway6.2.1.0 - 6.2.1.1_2 IT48302   Apply B2Bi 6.2.1.2, 6.2.2.1IBM Sterling B2B Integrator and IBM Sterling File Gateway6.2.2.0 - 6.2.2.0_1   IT48302  Apply B2Bi 6.2.2.1\n\n\n\n\n\n\n\nThe IIM versions of 6.1.2.8, 6.2.0.6, 6.2.1.2 and 6.2.2.1 are available on Fix Central http://www-933.ibm.com/support/fixcentral/swg/selectFixes . \n\n\n\nThe container version of 6.1.2.8, 6.2.0.6, 6.2.1.2 and 6.2.2.1 are available in IBM Entitled Registry.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "
ProductVersionAPARRemediation & Fix
IBM Sterling B2B Integrator and IBM Sterling File Gateway6.1.2.0 - 6.1.2.7_2 IT48302 Apply B2Bi 6.1.2.8, 6.2.0.6, 6.2.1.2, 6.2.2.1
IBM Sterling B2B Integrator and IBM Sterling File Gateway6.2.0.0 - 6.2.0.5_2 IT48302   Apply B2Bi 6.2.0.6, 6.2.1.2, 6.2.2.1
IBM Sterling B2B Integrator and IBM Sterling File Gateway6.2.1.0 - 6.2.1.1_2 IT48302   Apply B2Bi 6.2.1.2, 6.2.2.1
IBM Sterling B2B Integrator and IBM Sterling File Gateway6.2.2.0 - 6.2.2.0_1   IT48302  Apply B2Bi 6.2.2.1

The IIM versions of 6.1.2.8, 6.2.0.6, 6.2.1.2 and 6.2.2.1 are available on Fix Central

The container version of 6.1.2.8, 6.2.0.6, 6.2.1.2 and 6.2.2.1 are available in IBM Entitled Registry.

" } ] } ] }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-07-31T22:54:30.962525Z", "id": "CVE-2025-36298", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-07-31T22:54:44.854Z" } } ] } }