Description
IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through 6.2.2.0_1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published: 2026-07-30
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a cross‑site scripting flaw in IBM Sterling B2B Integrator and IBM Sterling File Gateway Web UI. An authenticated user can inject arbitrary JavaScript into the Web UI, enabling tampering of the interface and potentially exposing credentials from a trusted session. The flaw corresponds to CWE‑79, reflecting insufficient sanitization of user‑controlled input.

Affected Systems

IBM Sterling B2B Integrator and IBM Sterling File Gateway versions 6.2.2.0 and 6.2.2.0_1 are affected. These versions are listed in the vendor’s advisory and support documents.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity. The EPSS score is <1%, indicating a very low but nonzero likelihood of exploitation, and the vulnerability is not yet listed in CISA’s KEV catalog. The attack vector requires an authenticated session, so the attacker must have valid credentials to access the Web UI. With the injected script the attacker could manipulate the interface, relay sensitive information, and possibly compromise session integrity.

Generated by OpenCVE AI on August 4, 2026 at 11:44 UTC.

Remediation

Vendor Solution

ProductVersionAPARRemediation & FixIBM Sterling B2B Integrator and IBM Sterling File Gateway6.2.2.0 - 6.2.2.0_1  IT49587Apply B2Bi 6.2.2.1 The IIM versions of  6.2.2.1 is available on Fix Central http://www-933.ibm.com/support/fixcentral/swg/selectFixes .  The container version of 6.2.2.1 is available in IBM Entitled Registry.


OpenCVE Recommended Actions

  • Deploy IBM Sterling B2B Integrator and File Gateway 6.2.2.1, which contains the fix for the cross‑site scripting flaw.
  • Use IBM Fix Central and the IBM Entitled Registry to obtain and apply the IIM and container‑specific patches for version 6.2.2.1.
  • Implement a strict Content Security Policy to limit script execution on the Web UI as a temporary mitigation until the patch is applied.

Generated by OpenCVE AI on August 4, 2026 at 11:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Ibm aix
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Ibm aix
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Thu, 30 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through 6.2.2.0_1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title XSS Security Vulnerability in response header affects IBM Sterling B2B Integrator and IBM Sterling File Gateway
First Time appeared Ibm
Ibm sterling B2b Integrator
Ibm sterling File Gateway
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.2.0_1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.2.0_1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm sterling B2b Integrator
Ibm sterling File Gateway
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Ibm Aix Sterling B2b Integrator Sterling File Gateway
Linux Linux Kernel
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-30T16:14:23.516Z

Reserved: 2025-04-15T21:17:03.968Z

Link: CVE-2025-36431

cve-icon Vulnrichment

Updated: 2026-07-30T16:14:16.247Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T15:16:23.057

Modified: 2026-08-17T14:04:16.877

Link: CVE-2025-36431

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T11:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')