CVE-2023-47159: IBM Sterling File Gateway information disclosure
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to enumerate usernames due to an observable discrepancy in request responses.
Other sources
IBM Sterling File Gateway could allow an authenticated user to enumerate usernames due to an observable discrepancy in request responses.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47159?
CVE-2023-47159 is considered a medium severity vulnerability due to its potential to allow username enumeration.
How do I fix CVE-2023-47159?
To fix CVE-2023-47159, IBM recommends upgrading to a fixed version of Sterling File Gateway that addresses the issue.
Which versions of IBM Sterling File Gateway are affected by CVE-2023-47159?
IBM Sterling File Gateway versions from 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 are affected by CVE-2023-47159.
What kind of attack does CVE-2023-47159 facilitate?
CVE-2023-47159 facilitates an attack where an authenticated user can enumerate usernames due to discrepancies in request responses.
Is CVE-2023-47159 a remote or local vulnerability?
CVE-2023-47159 is a local vulnerability, as it requires authenticated access to the system to exploit.