First published: Wed Oct 06 2021(Updated: )
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote attacker to upload arbitrary files, caused by improper access controls. IBM X-Force ID: 199397.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling B2B Integrator | >=2.2.0.0<=5.2.6.5_4 | |
IBM Sterling B2B Integrator | >=6.0.0.0<=6.0.0.6 | |
IBM Sterling B2B Integrator | >=6.0.1.0<=6.0.3.4 | |
IBM Sterling B2B Integrator | >=6.1.0.0<=6.1.0.2 | |
<=2.2.0.0 - 5.2.6.5_4 | ||
<=6.0.0.0 - 6.0.0.6, 6.0.1.0 - 6.0.3.4 | ||
<=6.1.0.0 - 6.1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-20584.
The title of this vulnerability is 'IBM Sterling File Gateway could allow a remote attacker to upload arbitrary files caused by improper access controls.'
The severity rating of CVE-2021-20584 is 7.5 (high).
The affected software versions are IBM Sterling File Gateway 2.2.0.0 - 5.2.6.5_4, 6.0.0.0 - 6.0.0.6, 6.0.1.0 - 6.0.3.4, and 6.1.0.0 - 6.1.0.2.
You can patch this vulnerability by applying the relevant fix provided by IBM. Please refer to the vendor's support page for more information.