← back
CVE-2025-36134lowCWE-1275

IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure

8Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 3.7epss 0.3%
exploitation probability
0.3%top 79% of all CVEs
observed exploitation
nono source reports it
In short

IBM Sterling B2B Integrator and File Gateway have a cookie security flaw that could expose sensitive information. The cookie lacks proper protection settings, allowing attackers in certain scenarios to access data they shouldn't.

Technical detail

The affected versions (6.0.0.0-6.1.2.7, 6.2.0.0-6.2.0.5, 6.2.1.1) fail to set the SameSite attribute on a sensitive cookie, enabling potential cross-site request forgery (CSRF) or cross-site script inclusion attacks to leak session data. Exploitation requires user interaction in a cross-site context.

Summary generated and translated by AI from the official description.
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N