CVE Vulnerabilities

CVE-2025-36002

Password in Configuration File

Published: Oct 16, 2025 | Modified: Oct 25, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5, and 6.2.1.0 stores user credentials in configuration files which can be read by a local user.

Weakness

The product stores a password in a configuration file that might be accessible to actors who do not know the password.

Affected Software

Name Vendor Start Version End Version
Sterling_b2b_integrator Ibm 6.2.0.0 (including) 6.2.0.5_1 (excluding)
Sterling_b2b_integrator Ibm 6.2.1.0 (including) 6.2.1.0 (including)
Sterling_file_gateway Ibm 6.2.0.0 (including) 6.2.0.5_1 (excluding)
Sterling_file_gateway Ibm 6.2.1.0 (including) 6.2.1.0 (including)

Potential Mitigations

References