CVE-2025-2988

EUVD-2025-25219
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6.2.0.4, and 6.2.1.0 could disclose sensitive server information to an unauthorized user that could aid in further attacks against the system.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.7 LOW
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
ibmsterling_b2b_integrator
6.0.0.0 ≤
𝑥
< 6.1.2.7_1
ibmsterling_b2b_integrator
6.2.0.0 ≤
𝑥
< 6.2.0.5
ibmsterling_b2b_integrator
6.2.1.0
ibmsterling_file_gateway
6.0.0.0 ≤
𝑥
< 6.1.2.7_1
ibmsterling_file_gateway
6.2.0.0 ≤
𝑥
< 6.2.0.5
ibmsterling_file_gateway
6.2.1.0
𝑥
= Vulnerable software versions