PT-2020-17952 · Ibm · Ibm Sterling File Gateway
Published
2020-05-14
·
Updated
2020-05-15
·
CVE-2020-4259
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Sterling File Gateway versions 2.2.0.0 through 6.0.3.1
Description
The issue allows an authenticated user to manipulate
cookie information, potentially removing or adding modules from the cookie to access functionality they are not authorized to.Recommendations
For IBM Sterling File Gateway versions 2.2.0.0 through 6.0.3.1, consider restricting access to sensitive functionality until a patch is available. As a temporary workaround, limit the ability of authenticated users to manipulate
cookie information.Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Sterling File Gateway