IBM Sterling B2B Integrator and IBM Sterling File Gateway link injection
Published Jul 18, 2025
6.1
MEDIUMCVSS 3.1
EPSS 0.21%
Description
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.4 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser.
Affected products
-
- Version 6.0.0.0StatusaffectedConstraints<=6.1.2.7
- Version 6.2.0.0StatusaffectedConstraints<=6.2.0.4
- Version
-
- Version 6.0.0.0StatusaffectedConstraints<=6.1.2.7
- Version 6.2.0.0StatusaffectedConstraints<=6.2.0.4
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| IBM | Sterling B2B Integrator | unaffected |
| |||||||||
| IBM | Sterling File Gateway | unaffected |
|
- ≥ 6.0.0.0 · < 6.1.2.7_1
- ≥ 6.2 · < 6.2.0.5
- ≥ 6.0.0.0 · < 6.1.2.7_1
- ≥ 6.2.0.0 · < 6.2.0.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 - 6.1.2.7 IT47893 Apply B2Bi 6.1.2.7_1. 6.2.0.5 or 6.2.1.0 IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 - 6.2.0.4 IT47893 Apply B2Bi 6.2.0.5 or 6.2.1.0
The IIM versions of 6.1.2.7_1, 6.2.0.5 and 6.2.1.0 are available on Fix Central.
The container version of 6.1.2.7_1, 6.2.0.5 and 6.2.1.0 are available in IBM Entitled Registry.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-21923 Advisory
- https://www.ibm.com/support/pages/node/7240065 vendor-advisorypatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-21923 | Advisory | |
| https://www.ibm.com/support/pages/node/7240065 | vendor-advisorypatchVendor Advisory |
Change history (0)
No recorded changes yet.