4.3
CVE-2025-2827
- EPSS 0.17%
- Veröffentlicht 08.07.2025 15:15:27
- Zuletzt bearbeitet 02.08.2025 01:22:49
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM Sterling File Gateway information disclosure
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 could disclose sensitive installation directory information to an authenticated user that could be used in further attacks against the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Sterling File Gateway Version >= 6.0.0.0 < 6.1.2.7_1
Ibm ≫ Sterling File Gateway Version >= 6.2.0.0 < 6.2.0.5
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.381 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@us.ibm.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-548 Exposure of Information Through Directory Listing
A directory listing is inappropriately exposed, yielding potentially sensitive information to attackers.