cbcvebase.

Ibm Sterling File Gateway vulnerabilities

99 known vulnerabilities affecting ibm/sterling_file_gateway.

Total CVEs
99
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH12MEDIUM81LOW5

Vulnerabilities

Page 4 of 5
CVE-2014-6199P4MEDIUMCVSS 5.0v2.1v2.22015-01-10
CVE-2014-6199 [MEDIUM] CWE-399 CVE-2014-6199: The HTTP Server Adapter in IBM Sterling B2B Integrator 5.1 and 5.2.x and Sterling File Gateway 2.1 a The HTTP Server Adapter in IBM Sterling B2B Integrator 5.1 and 5.2.x and Sterling File Gateway 2.1 and 2.2 allows remote attackers to cause a denial of service (connection-slot exhaustion) via a crafted HTTP request.
nvd
CVE-2017-1549P4MEDIUMCVSS 5.4v2.22017-12-11
CVE-2017-1549 [MEDIUM] CWE-79 CVE-2017-1549: IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131289.
nvd
CVE-2017-1632P4MEDIUMCVSS 5.4v2.22017-12-11
CVE-2017-1632 [MEDIUM] CWE-79 CVE-2017-1632: IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133178.
nvd
CVE-2017-1575P4MEDIUMCVSS 5.5≥ 2.2.0, ≤ 2.2.6v2.2.0+1 more2018-07-20
CVE-2017-1575 [MEDIUM] CWE-327 CVE-2017-1575: IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) uses we IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) uses weaker than expected cryptographic algorithms that could allow a local attacker to decrypt highly sensitive information. IBM X-Force ID: 132032.
nvd
CVE-2023-47159P4MEDIUMCVSS 4.3≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2.0.0, ≤ 6.2.0.12025-01-27
CVE-2023-47159 [MEDIUM] CWE-204 CVE-2023-47159: IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authent IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to enumerate usernames due to an observable discrepancy in request responses.
nvd
CVE-2012-5936P4MEDIUMCVSS 5.0v2.1v2.22013-07-03
CVE-2012-5936 [MEDIUM] CWE-310 CVE-2012-5936: IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not set the secure IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
nvd
CVE-2013-5407P4MEDIUMCVSS 4.9v2.22013-12-21
CVE-2013-5407 [MEDIUM] CWE-20 CVE-2013-5407: IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not properly restrict use of FRAME IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not properly restrict use of FRAME elements, which allows remote authenticated users to bypass intended access restrictions or obtain sensitive information via a crafted web site, related to a "frame injection" issue.
nvd
CVE-2018-1470P4MEDIUMCVSS 4.3≥ 2.2.0, ≤ 2.2.6v2.2.0+1 more2018-07-20
CVE-2018-1470 [MEDIUM] CWE-200 CVE-2018-1470: IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote authenticated attacker to obtain IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote authenticated attacker to obtain sensitive information displayed in the URL that could lead to further attacks against the system. IBM X-Force ID: 140688.
nvd
CVE-2021-20563P4MEDIUMCVSS 4.3≥ 2.2.0.0, ≤ 6.1.0.3v2.2.0.0+1 more2021-09-23
CVE-2021-20563 [MEDIUM] CVE-2021-20563: IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote authenciated user to obtain s IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote authenciated user to obtain sensitive information. By sending a specially crafted request, the user could disclose a valid filepath on the server which could be used in further attacks against the system. IBM X-Force ID: 199234.
nvd
CVE-2025-1349P4MEDIUMCVSS 4.8≥ 6.0.0.0, < 6.1.2.7≥ 6.2.0.0, < 6.2.0.52025-06-18
CVE-2025-1349 [MEDIUM] CWE-79 CVE-2025-1349: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 throug IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted
nvd
CVE-2025-2694P4MEDIUMCVSS 4.8≥ 6.0.0.0, < 6.1.2.7_2≥ 6.2.0.0, < 6.2.0.5+2 more2025-09-04
CVE-2025-2694 [MEDIUM] CWE-79 CVE-2025-2694: IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling F IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lea
nvd
CVE-2021-20376P4MEDIUMCVSS 4.3v2.2.0.0v6.0.0.0+4 more2021-10-07
CVE-2021-20376 [MEDIUM] CWE-203 CVE-2021-20376: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated attacker to enumerate IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated attacker to enumerate usernames due to there being an observable discrepancy in returned messages. IBM X-Force ID: 195568.
nvd
CVE-2024-22316P4MEDIUMCVSS 4.3≥ 6.0.0.0, ≤ 6.1.2.5≥ 6.2.0.0, ≤ 6.2.0.12025-01-27
CVE-2024-22316 [MEDIUM] CWE-863 CVE-2024-22316: IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authent IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to perform unauthorized actions to another user's data due to improper access controls.
nvd
CVE-2025-2827P4MEDIUMCVSS 4.3≥ 6.0.0.0, < 6.1.2.7_1≥ 6.2.0.0, < 6.2.0.5+2 more2025-07-08
CVE-2025-2827 [MEDIUM] CWE-548 CVE-2025-2827: IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 could disclose IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 could disclose sensitive installation directory information to an authenticated user that could be used in further attacks against the system.
nvd
CVE-2024-54172P4MEDIUMCVSS 4.3≥ 6.0.0.0, < 6.1.2.7≥ 6.2.0.0, < 6.2.0.52025-06-18
CVE-2024-54172 [MEDIUM] CWE-352 CVE-2024-54172: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 throug IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
nvd
CVE-2013-0558P4MEDIUMCVSS 5.0v2.1v2.22013-07-03
CVE-2013-0558 [MEDIUM] CWE-200 CVE-2013-0558: IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to obtain sensitive information about application implementation via unspecified vectors.
nvd
CVE-2013-0539P4MEDIUMCVSS 5.0v2.1v2.22013-07-03
CVE-2013-0539 [MEDIUM] CWE-255 CVE-2013-0539: An unspecified third-party component in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Ga An unspecified third-party component in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 uses short session ID values, which makes it easier for remote attackers to hijack sessions, and consequently obtain sensitive information, via a brute-force attack.
nvd
CVE-2021-20372P4MEDIUMCVSS 4.3v2.2.0.0v6.0.1.0+6 more2021-10-07
CVE-2021-20372 [MEDIUM] CVE-2021-20372: IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote authenticated user to cause a IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote authenticated user to cause a denial of another user's service due to insufficient permission checking. IBM X-Force ID: 195518.
nvd
CVE-2020-4665P4MEDIUMCVSS 4.3≥ 2.2.0.0, ≤ 2.2.6.5≥ 6.0.0.0, ≤ 6.0.3.2+4 more2020-11-16
CVE-2020-4665 [MEDIUM] CVE-2020-4665: IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 does not set the secur IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can the
nvd
CVE-2020-4763P4MEDIUMCVSS 4.3≥ 2.2.0.0, ≤ 2.2.6.5≥ 6.0.0.0, ≤ 6.0.3.2+4 more2020-11-16
CVE-2020-4763 [MEDIUM] CVE-2020-4763: IBM Sterling File Gateway 6.0.0.0 through 6.0.3.2 and 2.2.0.0 through 2.2.6.5 does not set the secur IBM Sterling File Gateway 6.0.0.0 through 6.0.3.2 and 2.2.0.0 through 2.2.6.5 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can the
nvd
Ibm Sterling File Gateway vulnerabilities | cvebase