cbcvebase.
CVE-2025-36134
published 2025-11-25

CVE-2025-36134: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could disclose sensitive information…

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie.

Affected

10 ranges
VendorProductVersion rangeFixed in
ibmsterling_b2b_integrator
ibmsterling_b2b_integrator>= 6.0.0.0 < 6.1.2.7_26.1.2.7_2
ibmsterling_b2b_integrator6.0.0.0 – 6.1.2.7
ibmsterling_b2b_integrator>= 6.2.0.0 < 6.2.0.5_16.2.0.5_1
ibmsterling_b2b_integrator6.2.0.0 – 6.2.0.5
ibmsterling_file_gateway
ibmsterling_file_gateway>= 6.0.0.0 < 6.1.2.7_26.1.2.7_2
ibmsterling_file_gateway6.0.0.0 – 6.1.2.7
ibmsterling_file_gateway>= 6.2.0.0 < 6.2.0.5_16.2.0.5_1
ibmsterling_file_gateway6.2.0.0 – 6.2.0.5