Exposure of Sensitive System Information to an Unauthorized Control Sphere in IBM Sterling File Gateway and IBM Sterling B2B Integrator - CVE-2025-2667
Published: September 8, 2025
Vulnerability identifier: #VU114928
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-2667
CWE-ID: CWE-497
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote privileged user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote privileged user can gain unauthorized access to sensitive information on the system.
Affected software
IBM Sterling File Gateway
IBM Sterling B2B Integrator
IBM Sterling B2B Integrator
How to mitigate CVE-2025-2667
Install updates from vendor's website.
IBM Sterling File Gateway - addressed in versions 6.1.2.7.2, 6.2.0.5, 6.2.1.1
IBM Sterling B2B Integrator - addressed in versions 6.1.2.7.2, 6.2.0.5, 6.2.1.1
IBM Sterling B2B Integrator - addressed in versions 6.1.2.7.2, 6.2.0.5, 6.2.1.1