CVE-2025-36002: IBM Sterling b2b Integrator

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5, and 6.2.1.0 stores user credentials in configuration files which can be read by a local user.

Affected products

  • IBM Sterling b2b Integrator: from 6.2.0.0, before 6.2.0.5_1 (fixed in 6.2.0.5_1); version 6.2.1.0 only
  • IBM Sterling File Gateway: from 6.2.0.0, before 6.2.0.5_1 (fixed in 6.2.0.5_1); version 6.2.1.0 only

Published 2025-10-16. Last modified 2026-06-17.