CVE-2025-3630 MEDIUM

CVE-2025-3630: IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting

Vendor Ibm
Product Sterling B2B Integrator
Weakness CWE-79 · XSS
Published July 8, 2025
Last update August 24, 2025

CVSS base score

6.4/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Key dates

02Disclosure timeline

July 8, 2025 CVE published
August 24, 2025 Record updated