CVE-2021-20473: Medium severity ibm sterling file gateway vulnerability
IBM Sterling File Gateway User Interface 2.2.0.0 through 6.1.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 196944.
Other sources
IBM Sterling File Gateway User Interface does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2021-20473.
What is the severity of CVE-2021-20473?
The severity of CVE-2021-20473 is medium with a severity value of 6.5.
Which product is affected by CVE-2021-20473?
IBM Sterling File Gateway is affected by CVE-2021-20473.
What versions of IBM Sterling File Gateway are affected by CVE-2021-20473?
Versions 2.2.0.0 through 5.2.6.5_3, 6.0.0.0 through 6.0.3.4, and 6.1.0.0 through 6.1.0.1 of IBM Sterling File Gateway are affected by CVE-2021-20473.
How can I fix CVE-2021-20473?
To fix CVE-2021-20473, apply the patch provided by IBM. The patch can be downloaded from IBM's support website.