CVE-2023-47714: IBM Sterling File Gateway cross-site scripting
IBM Sterling File Gateway 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 271531.
Other sources
IBM Sterling File Gateway is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47714?
CVE-2023-47714 is categorized as a moderate severity cross-site scripting vulnerability.
How do I fix CVE-2023-47714?
To fix CVE-2023-47714, upgrade to the latest version of IBM Sterling File Gateway that resolves the XSS vulnerability.
Which versions of IBM Sterling File Gateway are affected by CVE-2023-47714?
CVE-2023-47714 affects IBM Sterling File Gateway versions 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0.
What types of attacks can be executed due to CVE-2023-47714?
Due to CVE-2023-47714, an attacker can execute arbitrary JavaScript code in the Web UI, potentially leading to unauthorized access to user credentials.
Is user action required to exploit CVE-2023-47714?
Yes, CVE-2023-47714 requires user interaction, as the vulnerability is exploited through the input of malicious scripts in the Web UI.