What is CVE-2025-36431?
This vulnerability in IBM Sterling B2B Integrator and File Gateway allows an authenticated user to embed arbitrary JavaScript code in the Web UI, potentially altering its intended functionality. Organizations using the affected versions should immediately apply security updates and restrict user inputs.
Azərbaycanca: IBM Sterling B2B Integrator və File Gateway məhsullarında aşkarlanan bu boşluq autentifikasiya olunmuş istifadəçiyə Web UI-da ixtiyari JavaScript kodu yerləşdirməyə imkan verir ki, bu da funksionallığın dəyişdirilməsinə səbəb ola bilər. Təsirə məruz qalan versiyaları işlədən təşkilatlar dərhal təhlükəsizlik yeniləmələrini tətbiq etməli və istifadəçi girişlərini məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: IBM
FAQ2
Does exploiting CVE-2025-36431 require the attacker to be authenticated?
Yes, this vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI.
Which IBM products are affected by CVE-2025-36431?
This vulnerability affects IBM Sterling B2B Integrator and File Gateway products.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.