Description
IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 Ebics server component is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published: 2026-07-30
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerable Ebics server component in IBM Sterling B2B Integrator and IBM Sterling File Gateway allows an authenticated user to embed arbitrary JavaScript into the web interface. This cross‑site scripting flaw, identified as CWE‑79, can alter intended functionality and potentially expose credentials stored in the user session.

Affected Systems

Affected products include IBM Sterling B2B Integrator versions 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1, as well as IBM Sterling File Gateway covering the same ranges.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity. The EPSS score of 0.00162, a value well below 1%, indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited widespread exploitation. Attack requires authentication to the web UI; an attacker with valid credentials could inject the malicious script, so the risk is confined to environments where privileged access is compromised. Regular monitoring of user activity and enforcing least privilege can help mitigate exploitation until a patch is applied.

Generated by OpenCVE AI on August 2, 2026 at 05:18 UTC.

Remediation

Vendor Solution

ProductVersionAPARRemediation & FixIBM Sterling B2B Integrator and IBM Sterling File Gateway6.1.2.0 - 6.1.2.7_2 IT48302 Apply B2Bi 6.1.2.8, 6.2.0.6, 6.2.1.2, 6.2.2.1IBM Sterling B2B Integrator and IBM Sterling File Gateway6.2.0.0 - 6.2.0.5_2 IT48302   Apply B2Bi 6.2.0.6, 6.2.1.2, 6.2.2.1IBM Sterling B2B Integrator and IBM Sterling File Gateway6.2.1.0 - 6.2.1.1_2 IT48302   Apply B2Bi 6.2.1.2, 6.2.2.1IBM Sterling B2B Integrator and IBM Sterling File Gateway6.2.2.0 - 6.2.2.0_1   IT48302  Apply B2Bi 6.2.2.1 The IIM versions of 6.1.2.8, 6.2.0.6, 6.2.1.2 and 6.2.2.1 are available on Fix Central http://www-933.ibm.com/support/fixcentral/swg/selectFixes .  The container version of 6.1.2.8, 6.2.0.6, 6.2.1.2 and 6.2.2.1 are available in IBM Entitled Registry.


OpenCVE Recommended Actions

  • Upgrade to IBM Sterling B2B Integrator version 6.1.2.8, 6.2.0.6, 6.2.1.2, or 6.2.2.1 and the corresponding IBM Sterling File Gateway versions; apply the APAR IT48302 to install the fixed releases.
  • For container deployments, pull the updated images for the same versions from the IBM Entitled Registry and replace the running containers.
  • Until the patch is applied, restrict web UI access to trusted administrators and monitor for anomalous script injection attempts.

Generated by OpenCVE AI on August 2, 2026 at 05:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Ibm aix
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Ibm aix
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Fri, 31 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 Ebics server component is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title Security Vulnerability in Ebics server affects IBM Sterling B2B Integrator and IBM Sterling File Gateway
First Time appeared Ibm
Ibm sterling B2b Integrator
Ibm sterling File Gateway
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:sterling_b2b_integrator:6.1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.1.2.7_2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.0.5_2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.1.1_2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.2.0_1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.1.2.7_2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.0.5_2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.1.1_2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.2.0_1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm sterling B2b Integrator
Ibm sterling File Gateway
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Ibm Aix Sterling B2b Integrator Sterling File Gateway
Linux Linux Kernel
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-31T22:54:44.854Z

Reserved: 2025-04-15T21:16:48.650Z

Link: CVE-2025-36298

cve-icon Vulnrichment

Updated: 2026-07-31T22:54:39.711Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T15:16:22.110

Modified: 2026-08-17T13:58:14.720

Link: CVE-2025-36298

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T05:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')