PT-2025-1529 · Ibm · Ibm Sterling File Gateway
Published
2024-11-14
·
Updated
2025-01-27
·
CVE-2023-47159
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Sterling File Gateway versions 6.0.0.0 through 6.1.2.5
IBM Sterling File Gateway versions 6.2.0.0 through 6.2.0.1
Description
The issue is related to an observable discrepancy in request responses, which could allow an authenticated user to enumerate usernames. This discrepancy may enable a remote attacker to gain unauthorized access to protected information.
Recommendations
For versions 6.0.0.0 through 6.1.2.5, consider restricting access to sensitive information until a patch is available.
For versions 6.2.0.0 through 6.2.0.1, avoid using the vulnerable functionality related to request responses until the issue is resolved.
As a temporary workaround, consider disabling the functionality that allows username enumeration until a patch is available.
Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Sterling File Gateway