First published: Mon Dec 11 2017(Updated: )
IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131289.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling File Gateway | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2017-1549.
The severity of the vulnerability is medium.
The CWE ID for this vulnerability is CWE-79.
The affected software for this vulnerability is IBM Sterling File Gateway 2.2.
This vulnerability can be exploited by embedding arbitrary JavaScript code in the Web UI of IBM Sterling File Gateway 2.2.