CVE-2025-36002

EUVD-2025-34766
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5, and 6.2.1.0 stores user credentials in configuration files which can be read by a local user.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
ibmsterling_b2b_integrator
6.2.0.0 ≤
𝑥
< 6.2.0.5_1
ibmsterling_b2b_integrator
6.2.1.0
ibmsterling_file_gateway
6.2.0.0 ≤
𝑥
< 6.2.0.5_1
ibmsterling_file_gateway
6.2.1.0
𝑥
= Vulnerable software versions