CVE-2025-36134
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie.
Scoring
- Severity
- LOW
- CVSS base score
- 3.7
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.30%
- CWE
- CWE-1275
- Published
- 2025-11-25
- Last modified
- 2026-03-13
Affected products
- IBM Sterling B2B Integrator
- IBM Sterling B2B Integrator
- IBM Sterling B2B Integrator
- IBM Sterling File Gateway
- IBM Sterling File Gateway
- IBM Sterling File Gateway
Weakness type
Related vulnerabilities
- CVE-2026-81888 — @hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking
- CVE-2026-73847 — Emlog: Missing CSRF protection in AI Assistant execute_tool leads to full database compromise and admin account takeover
- CVE-2026-55688 — AsyncHttpClient: Cookie stored for an unrelated domain (cookie tossing) via ThreadSafeCookieStore
- CVE-2026-8409 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete
- CVE-2026-8410 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete
- CVE-2026-8411 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete
- CVE-2026-8412 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache
- CVE-2026-8413 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design