4
CVE-2025-1348
- EPSS 0.02%
- Published 18.06.2025 16:19:48
- Last modified 25.07.2025 17:57:57
- Source psirt@us.ibm.com
- Teams watchlist Login
- Open Login
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 could allow a local user to obtain sensitive information from a user’s web browser cache due to not using a suitable caching policy.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Data is provided by the National Vulnerability Database (NVD)
Ibm ≫ Sterling B2b Integrator SwEditionstandard Version >= 6.0.0.0 < 6.1.2.7
Ibm ≫ Sterling B2b Integrator SwEditionstandard Version >= 6.2 < 6.2.0.5
Ibm ≫ Sterling File Gateway Version >= 6.0.0.0 < 6.1.2.7
Ibm ≫ Sterling File Gateway Version >= 6.2.0.0 < 6.2.0.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.02% | 0.041 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
psirt@us.ibm.com | 4 | 2.5 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-525 Use of Web Browser Cache Containing Sensitive Information
The web application does not use an appropriate caching policy that specifies the extent to which each web page and associated form fields should be cached.