CVE-2021-20481: XSS
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 197503.
Other sources
IBM Sterling File Gateway is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of the IBM Sterling File Gateway vulnerability?
The vulnerability ID of the IBM Sterling File Gateway vulnerability is CVE-2021-20481.
What is the severity of CVE-2021-20481?
The severity of CVE-2021-20481 is medium, with a severity value of 6.1.
What is the affected software?
The affected software is IBM Sterling File Gateway versions 2.2.0.0 through 6.1.1.0.
How can the IBM Sterling File Gateway vulnerability be exploited?
The vulnerability allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
How can I patch the IBM Sterling File Gateway vulnerability?
You can patch the IBM Sterling File Gateway vulnerability by applying the relevant fixes provided by IBM.