Reverse Tabnabbing in IBM Sterling B2B Integrator and IBM Sterling File Gateway - CVE-2025-33014

 

Reverse Tabnabbing in IBM Sterling B2B Integrator and IBM Sterling File Gateway - CVE-2025-33014

Published: July 21, 2025


Vulnerability identifier: #VU113088
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-33014
CWE-ID: CWE-1022
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability exists due to IBM Sterling B2B Integrator Standard Edition uses a web link with untrusted references to an external site. A remote user can exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser.


Affected software

IBM Sterling B2B Integrator
IBM Sterling File Gateway

How to mitigate CVE-2025-33014

Install updates from vendor's website.

IBM Sterling B2B Integrator - addressed in versions 6.1.2.7, 6.2.0.5, 6.2.1.0
IBM Sterling File Gateway - addressed in versions 6.1.2.7, 6.2.0.5, 6.2.1.0

External References

Related Security Bulletins