CVE-2025-33014

CWE-10223 documents3 sources
Severity
6.1MEDIUM
EPSS
0.0%
top 88.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 18

Description

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.4 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages4 packages

NVDibm/sterling_file_gateway6.0.0.06.1.2.7_1+1
CVEListV5ibm/sterling_file_gateway6.0.0.06.1.2.7+1
NVDibm/sterling_b2b_integrator6.0.0.06.1.2.7_1+1
CVEListV5ibm/sterling_b2b_integrator6.0.0.06.1.2.7+1

🔴Vulnerability Details

2
GHSA
GHSA-pr3f-84fh-7r83: IBM Sterling B2B Integrator and IBM Sterling File Gateway 62025-07-18
CVEList
IBM Sterling B2B Integrator and IBM Sterling File Gateway link injection2025-07-18
CVE-2025-33014 (MEDIUM CVSS 6.1) | IBM Sterling B2B Integrator and IBM | cvebase.io