CVE Vulnerabilities

CVE-2025-36002

Password in Configuration File

Published: Oct 16, 2025 | Modified: Oct 25, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5, and 6.2.1.0 stores user credentials in configuration files which can be read by a local user.

Weakness

The product stores a password in a configuration file that might be accessible to actors who do not know the password.

Affected Software

NameVendorStart VersionEnd Version
Sterling_b2b_integratorIbm6.2.0.0 (including)6.2.0.5_1 (excluding)
Sterling_b2b_integratorIbm6.2.1.0 (including)6.2.1.0 (including)
Sterling_file_gatewayIbm6.2.0.0 (including)6.2.0.5_1 (excluding)
Sterling_file_gatewayIbm6.2.1.0 (including)6.2.1.0 (including)

Potential Mitigations

References