CVE-2020-4658Cross-site Scripting in IBM Sterling File Gateway

Severity
6.1MEDIUMNVD
EPSS
0.2%
top 59.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 16
Latest updateMay 24

Description

IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186095.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDibm/sterling_file_gateway2.2.0.06.0.3.2
CVEListV5ibm/sterling_file_gateway2.2.0.0, 6.0.3.2+1

🔴Vulnerability Details

3
GHSA
GHSA-vr5w-372j-c5g6: IBM Sterling File Gateway 22022-05-24
CVEList
CVE-2020-4658: IBM Sterling File Gateway 22020-12-16
OSV
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 regression2020-12-13
CVE-2020-4658 — Cross-site Scripting in IBM | cvebase