Unprotected storage of credentials in IBM Sterling B2B Integrator and IBM Sterling File Gateway - CVE-2025-36002

 

Unprotected storage of credentials in IBM Sterling B2B Integrator and IBM Sterling File Gateway - CVE-2025-36002

Published: October 21, 2025


Vulnerability identifier: #VU117413
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-36002
CWE-ID: CWE-256
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to other users' credentials.

The vulnerability exists due to application stored credentials in plain text in a configuration file on the system. A local user can view contents of the configuration file and gain access to passwords for 3rd party integration.


Affected software

IBM Sterling B2B Integrator
IBM Sterling File Gateway

How to mitigate CVE-2025-36002

Install updates from vendor's website.

IBM Sterling B2B Integrator - addressed in versions 6.2.0.5.1, 6.2.1.1
IBM Sterling File Gateway - addressed in versions 6.2.0.5.1, 6.2.1.1

External References

Related Security Bulletins