PT-2025-1529 · Ibm · Ibm Sterling File Gateway

Published

2024-11-14

·

Updated

2025-01-27

·

CVE-2023-47159

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Sterling File Gateway versions 6.0.0.0 through 6.1.2.5 IBM Sterling File Gateway versions 6.2.0.0 through 6.2.0.1
Description The issue is related to an observable discrepancy in request responses, which could allow an authenticated user to enumerate usernames. This discrepancy may enable a remote attacker to gain unauthorized access to protected information.
Recommendations For versions 6.0.0.0 through 6.1.2.5, consider restricting access to sensitive information until a patch is available. For versions 6.2.0.0 through 6.2.0.1, avoid using the vulnerable functionality related to request responses until the issue is resolved. As a temporary workaround, consider disabling the functionality that allows username enumeration until a patch is available.

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

BDU:2025-01364
CVE-2023-47159

Affected Products

Ibm Sterling File Gateway