First published: Fri Dec 11 2020(Updated: )
IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186095.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling File Gateway | <=2.2.0.0 - 6.0.3.2 | |
IBM Sterling File Gateway | >=2.2.0.0<=6.0.3.2 | |
HPE HP-UX | ||
IBM AIX | ||
IBM OS/400 | ||
Linux Kernel | ||
Microsoft Windows | ||
Oracle Solaris SPARC |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4658 is a cross-site scripting vulnerability in IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2.
This vulnerability allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
As a user, you can exploit this vulnerability by embedding arbitrary JavaScript code in the Web UI of IBM Sterling File Gateway.
The severity of CVE-2020-4658 is medium, with a CVSS score of 6.1.
To fix this vulnerability, apply the official patch provided by IBM Sterling File Gateway.