ZeroHour

CVE-2025-36115

CVSS 3.1
6.5 medium
EPSS
<1%p4
Published
()
Modified
Description

IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0.00 through 5.2.0.12 does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system.

Vendors
ibm
Products
sterling connect\
Weakness
CWE-384
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.