5.3
CVE-2025-36112
- EPSS 0.03%
- Veröffentlicht 24.11.2025 18:25:03
- Zuletzt bearbeitet 01.12.2025 16:05:56
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could reveal sensitive server IP configuration information to an unauthorized user.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Sterling B2b Integrator Version >= 6.0.0.0 < 6.1.2.7_2
Ibm ≫ Sterling B2b Integrator Version >= 6.2.0.0 < 6.2.0.5_1
Ibm ≫ Sterling B2b Integrator Version6.2.1.1
Ibm ≫ Sterling File Gateway Version >= 6.0.0.0 < 6.1.2.7_2
Ibm ≫ Sterling File Gateway Version >= 6.2.0.0 < 6.2.0.5_1
Ibm ≫ Sterling File Gateway Version6.2.1.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.094 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@us.ibm.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.