CVE-2020-4658: XSS
IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186095.
Other sources
IBM Sterling File Gateway is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is IBM Sterling File Gateway vulnerability CVE-2020-4658?
CVE-2020-4658 is a cross-site scripting vulnerability in IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2.
What is the impact of IBM Sterling File Gateway vulnerability CVE-2020-4658?
This vulnerability allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
How can I exploit CVE-2020-4658?
As a user, you can exploit this vulnerability by embedding arbitrary JavaScript code in the Web UI of IBM Sterling File Gateway.
How severe is vulnerability CVE-2020-4658?
The severity of CVE-2020-4658 is medium, with a CVSS score of 6.1.
How can I fix vulnerability CVE-2020-4658?
To fix this vulnerability, apply the official patch provided by IBM Sterling File Gateway.