CVE-2021-20376: Medium severity ibm sterling file gateway vulnerability
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated attacker to enumerate usernames due to there being an observable discrepancy in returned messages. IBM X-Force ID: 195568.
Other sources
IBM Sterling File Gateway could allow an authenticated attacker to enumerate usernames due to there being an observable discrepancy in returned messages.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-20376?
CVE-2021-20376 is a vulnerability in IBM Sterling File Gateway that could allow an authenticated attacker to enumerate usernames.
How does CVE-2021-20376 affect IBM Sterling File Gateway?
CVE-2021-20376 affects IBM Sterling File Gateway versions 2.2.0.0 through 6.1.1.0.
What is the severity of CVE-2021-20376?
CVE-2021-20376 has a severity rating of 4.3 (medium).
How can an attacker exploit CVE-2021-20376?
An authenticated attacker can exploit CVE-2021-20376 to enumerate usernames by exploiting an observable discrepancy in returned messages.
Is there a patch available for CVE-2021-20376?
Yes, a patch is available for CVE-2021-20376. You can find it on IBM's support website.