SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2025-36298

MEDIUM · CVSS 5.4 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The Ebics server component in specific versions of IBM Sterling B2B Integrator and IBM Sterling File Gateway is vulnerable to cross-site scripting, allowing authenticated users to inject arbitrary JavaScript into the Web UI. This could lead to unauthorized access and potential credential disclosure within trusted sessions. Organizations using these affected products should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2025-36298
Severity
MEDIUM
CVSS
5.4
EPSS
0.17%
Java

Original NVD Description

IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 Ebics server component is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Related CVEs

Other vulnerabilities affecting the same vendor(s)