PT-2025-2311 · Ibm · Ibm Sterling File Gateway
Published
2024-11-14
·
Updated
2025-01-27
·
CVE-2024-22316
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Sterling File Gateway versions 6.0.0.0 through 6.1.2.5
IBM Sterling File Gateway versions 6.2.0.0 through 6.2.0.1
Description
The issue is related to improper access controls, which could allow an authenticated user to perform unauthorized actions on another user's data.
Recommendations
For versions 6.0.0.0 through 6.1.2.5, update to a version that includes proper access controls to prevent unauthorized actions.
For versions 6.2.0.0 through 6.2.0.1, update to a version that includes proper access controls to prevent unauthorized actions.
As a temporary workaround, consider restricting access to sensitive data and implementing additional security measures to minimize the risk of exploitation.
Fix
Incorrect Authorization
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Sterling File Gateway