Junglewise Threat Intelligence

CVE-2025-36431: IBM Sterling B2B Integrator and File Gateway cross-site scripting in Web UI

CVE-2025-36431 · Severity: medium · CVSS 5.4 · Published 2026-07-30

Executive brief

IBM Sterling B2B Integrator and Sterling File Gateway, which are used by organizations to securely exchange and manage large volumes of electronic data with partners, are affected by a security flaw in their web interface. An authenticated user could inject malicious scripts into the system's management console. If another user views the affected page, the script could run in their browser, potentially allowing the attacker to steal login credentials or perform unauthorized actions within the application.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in IBM Sterling B2B Integrator and IBM Sterling File Gateway versions 6.2.2.0 through 6.2.2.0_1. The flaw is rooted in the improper neutralization of input during web page generation (CWE-79), specifically involving response headers. An authenticated attacker can exploit this by embedding malicious JavaScript code into the Web UI. Successful exploitation requires a victim to interact with the affected component, at which point the script executes in the context of the victim's session, potentially leading to session hijacking or credential disclosure. The issue is resolved in version 6.2.2.1.

Affected products

  • IBM Sterling B2B Integrator 6.2.2.0 - 6.2.2.0_1
  • IBM Sterling File Gateway 6.2.2.0 - 6.2.2.0_1

Timeline

  • 2026-07-21: disclosed: Initial publication by IBM
  • 2026-07-21: patched: Fix released in version 6.2.2.1
  • 2026-07-30: advisory: NVD publication date

References

Related threats