IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0.00 through 5.2.0.12 does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7257244 |
|
History
Tue, 20 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 20 Jan 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0.00 through 5.2.0.12 does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system. | |
| Title | Multiple vulnerabilities were addressed in IBM Sterling Connect:Express for UNIX. | |
| First Time appeared |
Ibm
Ibm sterling Connectexpress Adapter For Sterling B2b Integrator 520 |
|
| Weaknesses | CWE-384 | |
| CPEs | cpe:2.3:a:ibm:sterling_connectexpress_adapter_for_sterling_b2b_integrator_520:5.2.0.00:*:*:*:*:*:*:* cpe:2.3:a:ibm:sterling_connectexpress_adapter_for_sterling_b2b_integrator_520:5.2.0.12:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm sterling Connectexpress Adapter For Sterling B2b Integrator 520 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-01-20T15:51:47.539Z
Reserved: 2025-04-15T21:16:17.124Z
Link: CVE-2025-36115
Updated: 2026-01-20T15:51:39.611Z
Status : Received
Published: 2026-01-20T16:16:03.703
Modified: 2026-01-20T16:16:03.703
Link: CVE-2025-36115
No data.
OpenCVE Enrichment
No data.