Sensitive Cookie Disclosure in IBM Sterling B2B Integrator and Gateway
CVE-2025-36134

3.7LOW

Key Information:

Vendor

IBM

Vendor
CVE Published:
25 November 2025

What is CVE-2025-36134?

IBM's Sterling B2B Integrator and Sterling File Gateway are susceptible to a security issue that could lead to the exposure of sensitive information. The vulnerability arises from the absence or misconfiguration of the SameSite attribute on certain cookies, potentially allowing unauthorized access to confidential data. It is crucial for users of affected versions to examine their configurations and apply necessary patches to ensure the security of their systems.

Affected Version(s)

Sterling B2B Integrator 6.0.0.0 <= 6.1.2.7

Sterling B2B Integrator 6.2.0.0 <= 6.2.0.5

Sterling B2B Integrator 6.2.1.1

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.