PatchSiren cyber security CVE debrief
CVE-2025-36298 IBM CVE debrief
The CVE-2025-36298 record details a cross-site scripting vulnerability in the Ebics server component of IBM Sterling B2B Integrator and IBM Sterling File Gateway. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI, potentially altering intended functionality and leading to credentials disclosure within a trusted session. Security teams should review the CVE record and apply patches or updates as recommended by the vendor. The vulnerability has a CVSS score of 5.4 and a severity rating of MEDIUM.
- Vendor
- IBM
- Product
- Sterling B2B Integrator
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-30
- Original CVE updated
- 2026-08-17
- Advisory published
- 2026-07-30
- Advisory updated
- 2026-08-17
Who should care
Security teams responsible for IBM Sterling B2B Integrator and IBM Sterling File Gateway should review and apply patches. System administrators and users of affected versions should be aware of potential exploitation risks and take necessary precautions to protect their systems. This includes reviewing system configurations, monitoring for suspicious activity, and implementing compensating controls as needed.
Technical summary
The Ebics server component in IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to cross-site scripting. An authenticated user can embed arbitrary JavaScript code in the Web UI, potentially altering the intended functionality and leading to credentials disclosure within a trusted session.
Defensive priority
Medium-priority defensive review recommended due to potential for authenticated user exploitation.
Recommended defensive actions
- Review and apply vendor-provided patches or updates.
- Implement compensating controls such as Web Application Firewalls.
- Monitor for suspicious activity and exception tracking.
- Conduct inventory checks for affected systems.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
Evidence from official CVE and NVD sources indicates a cross-site scripting vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway Ebics server component. Authenticated users may embed arbitrary JavaScript code in the Web UI, potentially altering functionality and leading to credentials disclosure within a trusted session.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-36298 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-36298
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-36298 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-36298
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7280668
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.