Ibm Sterling File Gateway vulnerabilities
97 known vulnerabilities affecting ibm/sterling_file_gateway.
Total CVEs
97
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH11MEDIUM80LOW5
Vulnerabilities
Page 2 of 5
CVE-2024-54183MEDIUMCVSS 5.4≥ 6.0.0.0, < 6.1.2.7≥ 6.2.0.0, < 6.2.0.52025-06-18
CVE-2024-54183 [MEDIUM] CWE-79 CVE-2024-54183: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 throug
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted se
nvd
CVE-2025-1349MEDIUMCVSS 4.8≥ 6.0.0.0, < 6.1.2.7≥ 6.2.0.0, < 6.2.0.52025-06-18
CVE-2025-1349 [MEDIUM] CWE-79 CVE-2025-1349: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 throug
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4
is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted
nvd
CVE-2025-1348MEDIUMCVSS 4.0≥ 6.0.0.0, < 6.1.2.7≥ 6.2.0.0, < 6.2.0.52025-06-18
CVE-2025-1348 [MEDIUM] CWE-525 CVE-2025-1348: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 throug
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 could allow a local user to obtain sensitive information from a user’s web browser cache due to not using a suitable caching policy.
nvd
CVE-2024-54172MEDIUMCVSS 4.3≥ 6.0.0.0, < 6.1.2.7≥ 6.2.0.0, < 6.2.0.52025-06-18
CVE-2024-54172 [MEDIUM] CWE-352 CVE-2024-54172: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 throug
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
nvd
CVE-2024-47109MEDIUMCVSS 5.3≥ 6.0.0.0, < 6.1.2.7≥ 6.2.0.0, < 6.2.0.4+2 more2025-03-10
CVE-2024-47109 [MEDIUM] CWE-522 CVE-2024-47109: IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure th
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure the installation path of the server which could aid in further attacks against the system.
cvelistv5nvd
CVE-2024-22316MEDIUMCVSS 4.3≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2.0.0, ≤ 6.2.0.12025-01-27
CVE-2024-22316 [MEDIUM] CWE-863 CVE-2024-22316: IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authent
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to perform unauthorized actions to another user's data due to improper access controls.
cvelistv5nvd
CVE-2023-52292MEDIUMCVSS 5.4≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2.0.0, ≤ 6.2.0.32025-01-27
CVE-2023-52292 [MEDIUM] CWE-79 CVE-2023-52292: IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to store
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
cvelistv5nvd
CVE-2023-47159MEDIUMCVSS 4.3≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2.0.0, ≤ 6.2.0.12025-01-27
CVE-2023-47159 [MEDIUM] CWE-204 CVE-2023-47159: IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authent
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to enumerate usernames due to an observable discrepancy in request responses.
cvelistv5nvd
CVE-2023-47714MEDIUMCVSS 5.4≥ 6.0.0.0, ≤ 6.0.3.9≥ 6.1.0.0, ≤ 6.1.2.3+1 more2024-04-12
CVE-2023-47714 [MEDIUM] CWE-79 CVE-2023-47714: IBM Sterling File Gateway 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerabl
IBM Sterling File Gateway 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 271531.
cvelistv5nvd
CVE-2021-39086MEDIUMCVSS 5.3≥ 6.0.0.0, < 6.0.3.6≥ 6.1.0.0, < 6.1.0.5+7 more2022-08-16
CVE-2021-39086 [MEDIUM] CWE-209 CVE-2021-39086: IBM Sterling File Gateway 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.
IBM Sterling File Gateway 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 215889.
cvelistv5nvd
CVE-2020-4654MEDIUMCVSS 6.5≥ 2.2.0.0, < 5.2.6.5_4≥ 6.0.0.0, < 6.0.3.5+7 more2021-10-08
CVE-2020-4654 [MEDIUM] CVE-2020-4654: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensit
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensitive information due to improper permission control. IBM X-Force ID: 186090.
cvelistv5nvd
CVE-2021-20489HIGHCVSS 8.8≥ 2.2.0.0, ≤ 5.2.6.5_3≥ 6.0.0.0, ≤ 6.0.0.6+10 more2021-10-07
CVE-2021-20489 [HIGH] CWE-352 CVE-2021-20489: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 197790.
cvelistv5nvd
CVE-2021-20584HIGHCVSS 7.5v2.2.0.0v6.0.1.0+6 more2021-10-07
CVE-2021-20584 [HIGH] CVE-2021-20584: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote attacker to upload arbitrary
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote attacker to upload arbitrary files, caused by improper access controls. IBM X-Force ID: 199397.
cvelistv5nvd
CVE-2021-20552MEDIUMCVSS 4.3≥ 6.0.1.0, ≤ 6.1.0.2v6.0.1.0+1 more2021-10-07
CVE-2021-20552 [MEDIUM] CWE-209 CVE-2021-20552: IBM Sterling File Gateway 6.0.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive
IBM Sterling File Gateway 6.0.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199170.
cvelistv5nvd
CVE-2021-20372MEDIUMCVSS 4.3v2.2.0.0v6.0.1.0+6 more2021-10-07
CVE-2021-20372 [MEDIUM] CVE-2021-20372: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote authenticated user to cause a
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote authenticated user to cause a denial of another user's service due to insufficient permission checking. IBM X-Force ID: 195518.
cvelistv5nvd
CVE-2021-20561MEDIUMCVSS 6.1v2.2.0.0v6.0.1.0+6 more2021-10-07
CVE-2021-20561 [MEDIUM] CWE-79 CVE-2021-20561: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulner
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199230.
cvelistv5nvd
CVE-2021-20473MEDIUMCVSS 6.5≥ 2.2.0.0, ≤ 5.2.6.5_3≥ 6.0.0.0, ≤ 6.0.3.4+7 more2021-10-07
CVE-2021-20473 [MEDIUM] CWE-613 CVE-2021-20473: IBM Sterling File Gateway User Interface 2.2.0.0 through 6.1.1.0 does not invalidate session after l
IBM Sterling File Gateway User Interface 2.2.0.0 through 6.1.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 196944.
cvelistv5nvd
CVE-2021-20375MEDIUMCVSS 6.5v2.2.0.0v6.0.0.0+4 more2021-10-07
CVE-2021-20375 [MEDIUM] CVE-2021-20375: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to intercept and
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to intercept and replace a message sent by another user due to improper access controls. IBM X-Force ID: 195567.
cvelistv5nvd
CVE-2021-20376MEDIUMCVSS 4.3v2.2.0.0v6.0.0.0+4 more2021-10-07
CVE-2021-20376 [MEDIUM] CWE-203 CVE-2021-20376: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated attacker to enumerate
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated attacker to enumerate usernames due to there being an observable discrepancy in returned messages. IBM X-Force ID: 195568.
cvelistv5nvd
CVE-2021-20481MEDIUMCVSS 6.1≥ 2.2.0.0, ≤ 5.2.6.5_3≥ 6.0.0.0, ≤ 6.0.0.6+10 more2021-10-07
CVE-2021-20481 [MEDIUM] CWE-79 CVE-2021-20481: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulner
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 197503.
cvelistv5nvd