First published: Mon Mar 10 2025(Updated: )
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure the installation path of the server which could aid in further attacks against the system.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling File Gateway | >=6.0.0.0<=6.1.2.6>=6.2.0.0<=6.2.0.3 | |
IBM Sterling File Gateway | <=6.0.0.0 - 6.1.2.6 | |
IBM Sterling File Gateway | <=6.2.0.0 - 6.2.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-47109 has a medium severity level due to potential exposure of sensitive installation paths.
To fix CVE-2024-47109, update your IBM Sterling File Gateway to a version above 6.2.0.3 or apply any recommended patches from IBM.
CVE-2024-47109 affects IBM Sterling File Gateway versions from 6.0.0.0 to 6.1.2.6 and 6.2.0.0 to 6.2.0.3.
The potential risks include unauthorized disclosure of the server's installation path, which can be exploited for further attacks.
There is currently no public indication that CVE-2024-47109 is being actively exploited, but it poses a risk if unaddressed.