CVE-2025-36002

EUVD-2025-34766
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5, and 6.2.1.0 stores user credentials in configuration files which can be read by a local user.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
ibmCNA
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
Affected Products (NVD)
VendorProductVersion
ibmsterling_b2b_integrator
6.2.0.0 ≤
𝑥
< 6.2.0.5_1
ibmsterling_b2b_integrator
6.2.1.0
ibmsterling_file_gateway
6.2.0.0 ≤
𝑥
< 6.2.0.5_1
ibmsterling_file_gateway
6.2.1.0
𝑥
= Vulnerable software versions