216.73.217.22

CVE-2025-14504

· Published 13/03/2026 19:53 · Modified 13/03/2026 19:53

Labels: CVE-2025-14504 2026-03-13CVE-2025-14504CWE-79[email protected]

Essential information

Published
13/03/2026 19:53
Modified
13/03/2026 19:53
Author
Creator
CVSS
5.4 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CVSS metrics

Description

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
ibm / sterling b2b integrator cpe:2.3:a:ibm:sterling_b2b_integrator:6.1.0.0-6.1.2.7_2:*:*:*:*:*:*:*
ibm / sterling b2b integrator cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.0.0-6.2.0.5_1:*:*:*:*:*:*:*
ibm / sterling b2b integrator cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.1.0-6.2.1.1_1:*:*:*:*:*:*:*
ibm / sterling b2b integrator cpe:2.3:a:ibm:sterling_b2b_integrator:6.2.2.0:*:*:*:*:*:*:*
ibm / sterling file gateway cpe:2.3:a:ibm:sterling_file_gateway:6.1.0.0-6.1.2.7_2:*:*:*:*:*:*:*
ibm / sterling file gateway cpe:2.3:a:ibm:sterling_file_gateway:6.2.0.0-6.2.0.5_1:*:*:*:*:*:*:*
ibm / sterling file gateway cpe:2.3:a:ibm:sterling_file_gateway:6.2.1.0-6.2.1.1_1:*:*:*:*:*:*:*
ibm / sterling file gateway cpe:2.3:a:ibm:sterling_file_gateway:6.2.2.0:*:*:*:*:*:*:*

References