CVE-2025-36002

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5, and 6.2.1.0 stores user credentials in configuration files which can be read by a local user.
References
Link Resource
https://www.ibm.com/support/pages/node/7248129 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.1.0:*:*:*:*:*:*:*
OR cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

25 Oct 2025, 02:15

Type Values Removed Values Added
CWE CWE-260

21 Oct 2025, 14:23

Type Values Removed Values Added
First Time Ibm aix
Linux
Ibm sterling B2b Integrator
Microsoft
Ibm
Microsoft windows
Ibm sterling File Gateway
Linux linux Kernel
CPE cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
References () https://www.ibm.com/support/pages/node/7248129 - () https://www.ibm.com/support/pages/node/7248129 - Vendor Advisory

16 Oct 2025, 16:15

Type Values Removed Values Added
CWE CWE-256

16 Oct 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-16 15:15

Updated : 2025-10-25 02:15


NVD link : CVE-2025-36002

Mitre link : CVE-2025-36002

CVE.ORG link : CVE-2025-36002


JSON object : View

Products Affected

ibm

  • sterling_b2b_integrator
  • sterling_file_gateway
  • aix

microsoft

  • windows

linux

  • linux_kernel
CWE
CWE-260

Password in Configuration File

CWE-256

Plaintext Storage of a Password