CVE-2025-1349 Details
Description
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
A stored cross-site scripting vulnerability has been identified in IBM Sterling B2B Integrator and IBM Sterling File Gateway, affecting versions 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4. This vulnerability allows a privileged user to inject arbitrary JavaScript into the Web UI, potentially altering functionality and leading to credential disclosure within a trusted session.
Users can upgrade to IBM Sterling B2B Integrator or IBM Sterling File Gateway versions 6.1.2.7, 6.2.0.5, or 6.2.1.0. The IIM and container versions of these releases are available on Fix Central and in the IBM Entitled Registry, respectively.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7237109 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm sterling b2b integrator | >= 6.0.0.0, < 6.1.2.7 >= 6.2, < 6.2.0.5 |
CPE
Remediation
| |
| ibm sterling file gateway | >= 6.0.0.0, < 6.1.2.7 >= 6.2.0.0, < 6.2.0.5 |
CPE
Remediation
| |
| ibm aix | All versions |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 25, 2025 | Initial Analysis | [email protected] |
| Jun 18, 2025 | New CVE Received | [email protected] |