CVE-2025-2988

EUVD-2025-25219
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6.2.0.4, and 6.2.1.0 could disclose sensitive server information to an unauthorized user that could aid in further attacks against the system.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.7 LOW
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
ibmCNA
2.7 LOW
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 8%
Affected Products (NVD)
VendorProductVersion
ibmsterling_b2b_integrator
6.0.0.0 ≤
𝑥
< 6.1.2.7_1
ibmsterling_b2b_integrator
6.2.0.0 ≤
𝑥
< 6.2.0.5
ibmsterling_b2b_integrator
6.2.1.0
ibmsterling_file_gateway
6.0.0.0 ≤
𝑥
< 6.1.2.7_1
ibmsterling_file_gateway
6.2.0.0 ≤
𝑥
< 6.2.0.5
ibmsterling_file_gateway
6.2.1.0
𝑥
= Vulnerable software versions