CVE Vulnerabilities

CVE-2025-36134

Sensitive Cookie with Improper SameSite Attribute

Published: Nov 25, 2025 | Modified: Dec 01, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie.

Weakness

The SameSite attribute for sensitive cookies is not set, or an insecure value is used.

Affected Software

NameVendorStart VersionEnd Version
Sterling_b2b_integratorIbm6.0.0.0 (including)6.1.2.7_2 (excluding)
Sterling_b2b_integratorIbm6.2.0.0 (including)6.2.0.5_1 (excluding)
Sterling_b2b_integratorIbm6.2.1.1 (including)6.2.1.1 (including)
Sterling_file_gatewayIbm6.0.0.0 (including)6.1.2.7_2 (excluding)
Sterling_file_gatewayIbm6.2.0.0 (including)6.2.0.5_1 (excluding)
Sterling_file_gatewayIbm6.2.1.1 (including)6.2.1.1 (including)

Potential Mitigations

References