Cross-Site Scripting Vulnerability in IBM Sterling B2B Integrator and File Gateway
CVE-2025-36298
5.4MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 30 July 2026
What is CVE-2025-36298?
The Ebics server component of IBM Sterling B2B Integrator and Sterling File Gateway is affected by a cross-site scripting vulnerability that allows authenticated users to insert arbitrary JavaScript code into the Web UI. This can alter the intended functionality of the application and potentially lead to the disclosure of user credentials during trusted sessions. It is crucial for users of these products to apply the necessary security patches to mitigate the risks associated with this vulnerability.
Affected Version(s)
Sterling B2B Integrator 6.1.2.0 <= 6.1.2.7_2
Sterling B2B Integrator 6.2.0.0 <= 6.2.0.5_2
Sterling B2B Integrator 6.2.1.0 <= 6.2.1.1_2