Cross-Site Scripting Vulnerability in IBM Sterling B2B Integrator and File Gateway
CVE-2025-36298

5.4MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
30 July 2026

What is CVE-2025-36298?

The Ebics server component of IBM Sterling B2B Integrator and Sterling File Gateway is affected by a cross-site scripting vulnerability that allows authenticated users to insert arbitrary JavaScript code into the Web UI. This can alter the intended functionality of the application and potentially lead to the disclosure of user credentials during trusted sessions. It is crucial for users of these products to apply the necessary security patches to mitigate the risks associated with this vulnerability.

Affected Version(s)

Sterling B2B Integrator 6.1.2.0 <= 6.1.2.7_2

Sterling B2B Integrator 6.2.0.0 <= 6.2.0.5_2

Sterling B2B Integrator 6.2.1.0 <= 6.2.1.1_2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.