First published: Fri Dec 11 2020(Updated: )
IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186095.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling File Gateway | >=2.2.0.0<=6.0.3.2 | |
HP HP-UX | ||
IBM AIX | ||
IBM i | ||
Linux Linux kernel | ||
Microsoft Windows | ||
Oracle Solaris | ||
<=2.2.0.0 - 6.0.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4658 is a cross-site scripting vulnerability in IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2.
This vulnerability allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
As a user, you can exploit this vulnerability by embedding arbitrary JavaScript code in the Web UI of IBM Sterling File Gateway.
The severity of CVE-2020-4658 is medium, with a CVSS score of 6.1.
To fix this vulnerability, apply the official patch provided by IBM Sterling File Gateway.