CVE Vulnerabilities

CVE-2025-36134

Sensitive Cookie with Improper SameSite Attribute

Published: Nov 25, 2025 | Modified: Dec 01, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie.

Weakness

The SameSite attribute for sensitive cookies is not set, or an insecure value is used.

Affected Software

Name Vendor Start Version End Version
Sterling_b2b_integrator Ibm 6.0.0.0 (including) 6.1.2.7_2 (excluding)
Sterling_b2b_integrator Ibm 6.2.0.0 (including) 6.2.0.5_1 (excluding)
Sterling_b2b_integrator Ibm 6.2.1.1 (including) 6.2.1.1 (including)
Sterling_file_gateway Ibm 6.0.0.0 (including) 6.1.2.7_2 (excluding)
Sterling_file_gateway Ibm 6.2.0.0 (including) 6.2.0.5_1 (excluding)
Sterling_file_gateway Ibm 6.2.1.1 (including) 6.2.1.1 (including)

Potential Mitigations

References