CVE-2023-52292
- EPSS 0.22%
- Veröffentlicht 27.01.2025 16:15:29
- Zuletzt bearbeitet 06.11.2025 22:01:07
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality pote...
CVE-2023-47714
- EPSS 0.32%
- Veröffentlicht 12.04.2024 13:15:14
- Zuletzt bearbeitet 07.03.2025 12:36:39
IBM Sterling File Gateway 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality p...
CVE-2021-39086
- EPSS 0.92%
- Veröffentlicht 16.08.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:18:34
IBM Sterling File Gateway 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information...
CVE-2020-4654
- EPSS 0.74%
- Veröffentlicht 08.10.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 05:33:03
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensitive information due to improper permission control. IBM X-Force ID: 186090.
CVE-2021-20481
- EPSS 0.64%
- Veröffentlicht 07.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:46:38
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disc...
CVE-2021-20489
- EPSS 0.4%
- Veröffentlicht 07.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:46:39
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 197790.
CVE-2021-20552
- EPSS 0.98%
- Veröffentlicht 07.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:46:45
IBM Sterling File Gateway 6.0.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. ...
CVE-2021-20473
- EPSS 0.48%
- Veröffentlicht 07.10.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 05:46:37
IBM Sterling File Gateway User Interface 2.2.0.0 through 6.1.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 196944.
CVE-2021-20484
- EPSS 0.5%
- Veröffentlicht 23.09.2021 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:46:39
IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disc...
CVE-2021-20485
- EPSS 0.98%
- Veröffentlicht 23.09.2021 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:46:39
IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. ...