CVE-2025-33014
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.4 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.4
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS probability
- 0.21%
- CWE
- CWE-1022
- Published
- 2025-07-18
- Last modified
- 2026-03-13
Affected products
- IBM Sterling B2B Integrator
- IBM Sterling B2B Integrator
- IBM Sterling File Gateway
- IBM Sterling File Gateway
Weakness type
Related vulnerabilities
- CVE-2026-71555 — PILOS: Reverse tabnabbing in room description
- CVE-2025-59842 — JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
- CVE-2025-42941 — Reverse Tabnabbing vulnerability in SAP Fiori (Launchpad)
- CVE-2024-39727 — IBM Engineering Lifecycle Optimization - Engineering Insights tabnabbing
- CVE-2018-25089 — glb Meetup Tag Extension Link Attribute reverse tabnabbing
- CVE-2022-4927 — ualbertalib NEOSDiscovery _refworks.html.erb reverse tabnabbing
- CVE-2018-25058 — Twitter-Post-Fetcher Link Target twitterFetcher.js reverse tabnabbing
- CVE-2020-36624 — ahorner text-helpers translation.rb reverse tabnabbing