First published: Mon Dec 11 2017(Updated: )
IBM Sterling File Gateway 2.2 could allow an authenticated user to change other user's passwords. IBM X-Force ID: 131290.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling File Gateway | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1550 has a medium severity level as it allows authenticated users to change other users' passwords.
To fix CVE-2017-1550, upgrade IBM Sterling File Gateway to a version that addresses this vulnerability.
Users of IBM Sterling File Gateway version 2.2 are affected by CVE-2017-1550.
No, CVE-2017-1550 requires authentication, so it cannot be exploited remotely.
Exploitation of CVE-2017-1550 could lead to unauthorized access to user accounts through password changes.