Cross-Site Scripting Vulnerability in IBM Sterling B2B Integrator and File Gateway
CVE-2025-36431
5.4MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 30 July 2026
What is CVE-2025-36431?
IBM Sterling B2B Integrator and IBM Sterling File Gateway are susceptible to cross-site scripting due to a flaw that allows authenticated users to inject arbitrary JavaScript code into the web interface. This could result in unauthorized actions being executed in the context of a trusted user session, potentially leading to the exposure of sensitive information, including user credentials. It is crucial for organizations using these products to apply recommended security patches and ensure proper input validation to mitigate this risk.
Affected Version(s)
Sterling B2B Integrator 6.2.2.0 <= 6.2.2.0_1
Sterling File Gateway 6.2.2.0 <= 6.2.2.0_1