« Volver al listado

CVE-2025-36348

Estado: AnalizadaMedia (4.9)—

IBM Sterling B2B Integrator versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1, and IBM Sterling File Gateway versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1 may expose sensitive information to a remote privileged attacker due to the application returning detailed technical error messages in the browser.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-36348",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-36348",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-02-18T20:37:42.475767Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@us.ibm.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@us.ibm.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:sterling_b2b_integrator:6.1.0.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:sterling_b2b_integrator:6.1.2.7_2:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.0.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.0.5:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.1.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.1.1:*:*:*:*:*:*:*"
          ],
          "vendor": "IBM",
          "product": "Sterling B2B Integrator",
          "versions": [
            {
              "status": "affected",
              "version": "6.1.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.2.7_2"
            },
            {
              "status": "affected",
              "version": "6.2.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "6.2.0.5"
            },
            {
              "status": "affected",
              "version": "6.2.1.0",
              "versionType": "semver",
              "lessThanOrEqual": "6.2.1.1"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:ibm:sterling_file_gateway:6.1.0.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:sterling_file_gateway:6.1.2.7_2:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:sterling_file_gateway:6.2.0.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:sterling_file_gateway:6.2.0.5:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:sterling_file_gateway:6.2.1.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:sterling_file_gateway:6.2.1.1:*:*:*:*:*:*:*"
          ],
          "vendor": "IBM",
          "product": "Sterling File Gateway",
          "versions": [
            {
              "status": "affected",
              "version": "6.1.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.2.7_2"
            },
            {
              "status": "affected",
              "version": "6.2.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "6.2.0.5"
            },
            {
              "status": "affected",
              "version": "6.2.1.0",
              "versionType": "semver",
              "lessThanOrEqual": "6.2.1.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-02-17T22:18:43.783",
  "references": [
    {
      "url": "https://www.ibm.com/support/pages/node/7259769",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@us.ibm.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@us.ibm.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-209"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "IBM Sterling B2B Integrator versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1, and IBM Sterling File Gateway versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1 may expose sensitive information to a remote privileged attacker due to the application returning detailed technical error messages in the browser."
    },
    {
      "lang": "es",
      "value": "Las versiones de IBM Sterling B2B Integrator 6.1.0.0 a 6.1.2.7_2, 6.2.0.0 a 6.2.0.5 y 6.2.1.0 a 6.2.1.1, y las versiones de IBM Sterling File Gateway 6.1.0.0 a 6.1.2.7_2, 6.2.0.0 a 6.2.0.5 y 6.2.1.0 a 6.2.1.1 pueden exponer información sensible a un atacante en remoto con privilegios debido a que la aplicación devuelve mensajes de error técnicos detallados en el navegador."
    }
  ],
  "lastModified": "2026-06-17T09:14:39.190",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CF5BFBAA-B7B6-43FC-893D-F62E8AC28673",
              "versionEndExcluding": "6.1.2.8",
              "versionStartIncluding": "6.1.0.0"
            },
            {
              "criteria": "cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5E7BD82C-7A6C-44C3-BE64-FFF75700EED1",
              "versionEndExcluding": "6.2.0.5_1",
              "versionStartIncluding": "6.2.0.0"
            },
            {
              "criteria": "cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "404D86E8-EE57-436C-B6B6-5C3715410123",
              "versionEndExcluding": "6.2.1.1_1",
              "versionStartIncluding": "6.2.1.0"
            },
            {
              "criteria": "cpe:2.3:a:ibm:sterling_file_gateway:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "00C60634-AE0C-4641-B645-0D0511A0070C",
              "versionEndExcluding": "6.1.2.8",
              "versionStartIncluding": "6.1.0.0"
            },
            {
              "criteria": "cpe:2.3:a:ibm:sterling_file_gateway:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6CF6DF92-A6D4-4FBB-8662-5BE9D814D911",
              "versionEndExcluding": "6.2.0.5_1",
              "versionStartIncluding": "6.2.0.0"
            },
            {
              "criteria": "cpe:2.3:a:ibm:sterling_file_gateway:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5261E09-9336-4301-A66D-FA39CE10E5B0",
              "versionEndExcluding": "6.2.1.1_1",
              "versionStartIncluding": "6.2.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@us.ibm.com"
}