Unprotected storage of credentials in IBM Sterling B2B Integrator and IBM Sterling File Gateway - CVE-2025-36002
Published: October 21, 2025
Vulnerability identifier: #VU117413
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-36002
CWE-ID: CWE-256
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to other users' credentials.
The vulnerability exists due to application stored credentials in plain text in a configuration file on the system. A local user can view contents of the configuration file and gain access to passwords for 3rd party integration.
Affected software
IBM Sterling B2B Integrator
IBM Sterling File Gateway
IBM Sterling File Gateway
How to mitigate CVE-2025-36002
Install updates from vendor's website.
IBM Sterling B2B Integrator - addressed in versions 6.2.0.5.1, 6.2.1.1
IBM Sterling File Gateway - addressed in versions 6.2.0.5.1, 6.2.1.1
IBM Sterling File Gateway - addressed in versions 6.2.0.5.1, 6.2.1.1