Cross-Site Scripting Vulnerability in IBM Sterling Connect:Express Adapter
CVE-2025-36113

5.4MEDIUM

What is CVE-2025-36113?

The IBM Sterling Connect:Express Adapter versions 5.2.0 to 5.2.0.12 are susceptible to a Cross-Site Scripting vulnerability. An authenticated user can exploit this flaw by injecting arbitrary JavaScript into the Web UI. This exploitation can manipulate the intended functions of the application, leading to potential credential disclosure within trusted sessions. Appropriate patches and security measures are recommended to mitigate this risk.

Affected Version(s)

Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 <= 5.2.0.12

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.