cbcvebase.

Ibm Sterling File Gateway vulnerabilities

99 known vulnerabilities affecting ibm/sterling_file_gateway.

Total CVEs
99
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH12MEDIUM81LOW5

Vulnerabilities

Page 2 of 5
CVE-2013-0560P4MEDIUMCVSS 6.5v2.1v2.22013-07-03
CVE-2013-0560 [MEDIUM] CVE-2013-0560: Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2012-5766.
nvd
CVE-2020-4654P4MEDIUMCVSS 6.5≥ 2.2.0.0, < 5.2.6.5_4≥ 6.0.0.0, < 6.0.3.5+7 more2021-10-08
CVE-2020-4654 [MEDIUM] CVE-2020-4654: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensit IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensitive information due to improper permission control. IBM X-Force ID: 186090.
nvd
CVE-2019-4423P4MEDIUMCVSS 5.3≥ 2.2.0.0, ≤ 6.0.1.0v2.2.0.0+1 more2019-09-30
CVE-2019-4423 [MEDIUM] CWE-22 CVE-2019-4423: IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 could allow a remote attacker to traverse director IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162769.
nvd
CVE-2026-3482P4MEDIUMCVSS 5.3≥ 6.2.0.0, ≤ 6.2.0.5_2≥ 6.2.1.0, ≤ 6.2.1.1_2+1 more2026-07-22
CVE-2026-3482 [MEDIUM] CWE-639 CVE-2026-3482: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 throug IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 could allow an unauthenticated user to read sensitive information by bypassing authentication through a specially crafted HTTP request.
nvd
CVE-2017-1550P4MEDIUMCVSS 6.5v2.22017-12-11
CVE-2017-1550 [MEDIUM] CVE-2017-1550: IBM Sterling File Gateway 2.2 could allow an authenticated user to change other user's passwords. IB IBM Sterling File Gateway 2.2 could allow an authenticated user to change other user's passwords. IBM X-Force ID: 131290.
nvd
CVE-2021-20375P4MEDIUMCVSS 6.5v2.2.0.0v6.0.0.0+4 more2021-10-07
CVE-2021-20375 [MEDIUM] CVE-2021-20375: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to intercept and IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to intercept and replace a message sent by another user due to improper access controls. IBM X-Force ID: 195567.
nvd
CVE-2020-4259P4MEDIUMCVSS 6.5≥ 2.2.0.0, ≤ 2.2.6.5_1≥ 6.0.0.0, ≤ 6.0.3.1+2 more2020-05-14
CVE-2020-4259 [MEDIUM] CWE-276 CVE-2020-4259: IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 could allow an authenticated user could manipulate IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 could allow an authenticated user could manipulate cookie information and remove or add modules from the cookie to access functionality not authorized to. IBM X-Force ID: 175638.
nvd
CVE-2021-20473P4MEDIUMCVSS 6.5≥ 2.2.0.0, ≤ 5.2.6.5_3≥ 6.0.0.0, ≤ 6.0.3.4+7 more2021-10-07
CVE-2021-20473 [MEDIUM] CWE-613 CVE-2021-20473: IBM Sterling File Gateway User Interface 2.2.0.0 through 6.1.1.0 does not invalidate session after l IBM Sterling File Gateway User Interface 2.2.0.0 through 6.1.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 196944.
nvd
CVE-2017-1548P4MEDIUMCVSS 5.3v2.22017-12-11
CVE-2017-1548 [MEDIUM] CWE-22 CVE-2017-1548: IBM Sterling File Gateway 2.2 could allow a remote attacker to traverse directories on the system. A IBM Sterling File Gateway 2.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 131288.
nvd
CVE-2017-1487P4MEDIUMCVSS 6.5v2.22017-12-07
CVE-2017-1487 [MEDIUM] CWE-200 CVE-2017-1487: IBM Sterling File Gateway 2.2 could allow an authenticated attacker to obtain sensitive information IBM Sterling File Gateway 2.2 could allow an authenticated attacker to obtain sensitive information such as login ids on the system. IBM X-Force ID: 128626.
nvd
CVE-2013-2982P4MEDIUMCVSS 6.5v2.1v2.22013-07-03
CVE-2013-2982 [MEDIUM] CVE-2013-2982: IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authentic IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to upload arbitrary files via unspecified vectors.
nvd
CVE-2013-2984P4MEDIUMCVSS 6.5v2.1v2.22013-07-03
CVE-2013-2984 [MEDIUM] CWE-22 CVE-2013-2984: Directory traversal vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gatew Directory traversal vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote authenticated users to read or modify files via unspecified vectors.
nvd
CVE-2025-36112P4MEDIUMCVSS 5.3≥ 6.0.0.0, < 6.1.2.7_2≥ 6.2.0.0, < 6.2.0.5_1+3 more2025-11-24
CVE-2025-36112 [MEDIUM] CWE-497 CVE-2025-36112: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 throug IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could reveal sensitive server IP configuration information to an unauthorized user.
nvd
CVE-2013-5413P4MEDIUMCVSS 4.3v2.22013-12-21
CVE-2013-5413 [MEDIUM] CWE-287 CVE-2013-5413: IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not invalidate a session upon a log IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not invalidate a session upon a logout action, which allows remote attackers to bypass authentication by leveraging an unattended workstation.
nvd
CVE-2013-0476P4MEDIUMCVSS 6.4v2.1v2.22013-07-03
CVE-2013-0476 [MEDIUM] CVE-2013-0476: IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to inject arbitrary FTP commands via unspecified vectors.
nvd
CVE-2018-1398P4MEDIUMCVSS 5.3≥ 2.2.0, ≤ 2.2.6v2.2.0+1 more2018-07-20
CVE-2018-1398 [MEDIUM] CWE-200 CVE-2018-1398: IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote attacker to download certain file IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote attacker to download certain files that could contain sensitive information. IBM X-Force ID: 138434.
nvd
CVE-2025-33014P4MEDIUMCVSS 6.1≥ 6.0.0.0, < 6.1.2.7_1≥ 6.2.0.0, < 6.2.0.5+2 more2025-07-18
CVE-2025-33014 [MEDIUM] CWE-1022 CVE-2025-33014: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 throug IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.4 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser.
nvd
CVE-2025-36002P4MEDIUMCVSS 5.5≥ 6.2.0.0, < 6.2.0.5_1v6.2.1.0+1 more2025-10-16
CVE-2025-36002 [MEDIUM] CWE-260 CVE-2025-36002: IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0 IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5, and 6.2.1.0 stores user credentials in configuration files which can be read by a local user.
nvd
CVE-2026-0835P4MEDIUMCVSS 5.4≥ 6.1.0.0, < 6.1.2.8≥ 6.2.0.0, < 6.2.0.5_2+2 more2026-03-13
CVE-2026-0835 [MEDIUM] CWE-79 CVE-2026-0835: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 are vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cr
nvd
CVE-2025-14504P4MEDIUMCVSS 5.4≥ 6.1.0.0, < 6.1.2.8≥ 6.2.0.0, < 6.2.0.5_2+5 more2026-03-13
CVE-2025-14504 [MEDIUM] CWE-79 CVE-2025-14504: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c
nvd
Ibm Sterling File Gateway vulnerabilities | cvebase