CVE-2020-4259: Medium severity ibm sterling file gateway vulnerability
IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 could allow an authenticated user could manipulate cookie information and remove or add modules from the cookie to access functionality not authorized to. IBM X-Force ID: 175638.
Other sources
IBM Sterling File Gateway could allow an authenticated user could manipulate cookie information and remove or add modules from the cookie to access functionality not authorized to.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4259?
The severity of CVE-2020-4259 is medium with a severity value of 6.5.
How does IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 allow an authenticated user to manipulate cookie information?
IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 allows an authenticated user to manipulate cookie information by removing or adding modules from the cookie.
Is there a patch available for CVE-2020-4259?
Yes, there is a patch available for CVE-2020-4259. You can download the patch from the IBM Support website.
What versions of IBM Sterling File Gateway are affected by CVE-2020-4259?
IBM Sterling File Gateway versions 2.2.0.0 through 2.2.6.5_1 and 6.0.0.0 through 6.0.3.1 are affected by CVE-2020-4259.
Are other operating systems vulnerable to CVE-2020-4259?
No, other operating systems such as HP-UX, IBM AIX, IBM i, Linux kernel, Microsoft Windows, and Oracle Solaris are not vulnerable to CVE-2020-4259.