← Vulnerability feed

Vulnerability record · CVE-2025-36134 · published 25 November 2025

CVE-2025-36134: Ibm sterling b2b integrator vulnerability

Ibm · Sterling B2b Integrator

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie.

7.5 CVSS 3.1 High EPSS 0.30% · top 79.9% CWE-1275 · CWE-1275
7.5CVSS 3.1 base score
0.30%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-36134 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2015-7450IBM products Java deserialization RCE via Commons CollectionsMultiple IBM analytics, business, IT infrastructure, and mobile/social products expose serialized-object interfaces that deserialize untrusted Java o…KEVEPSS 98%analysed9.8CVE-2023-50316Ibm sterling b2b integrator sql injection vulnerabilityIBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 is vulnerable to SQL injection. A remote attacker could send speciall…EPSS 0.35%9.8CVE-2022-22338Ibm sterling b2b integrator sql injection vulnerabilityIBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted S…EPSS 0.68%9.8CVE-2021-39085Ibm sterling b2b integrator sql injection vulnerabilityIBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to SQL injec…EPSS 0.92%9.8CVE-2021-29798Ibm sterling b2b integrator sql injection vulnerabilityIBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted S…EPSS 1.1%9.8CVE-2021-29903Ibm sterling b2b integrator sql injection vulnerabilityIBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted S…EPSS 1.1%9.3CVE-2012-5937Ibm gentran integration suite vulnerabilityUnspecified vulnerability in the CLA2 server in IBM Gentran Integration Suite 4.3, Sterling Integrator 5.0 and 5.1, and Sterling B2B Integrator 5.2, …EPSS 2.6%8.8CVE-2023-38739Ibm sterling b2b integrator cross-site request forgery vulnerabilityIBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-site request forgery which could allow an atta…EPSS 0.17%

Source: NIST National Vulnerability Database (record CVE-2025-36134), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.