Page 4 of 23 results (0.011 seconds)

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162769. IBM Sterling File Gateway versiones 2.2.0.0 hasta 6.0.1.0, podría permitir a un atacante remoto saltar directorios en el sistema. Un atacante podría enviar una petición URL especialmente diseñada que contenga secuencias de "dot dot" (/../) para visualizar archivos arbitrarios en el sistema. • https://exchange.xforce.ibmcloud.com/vulnerabilities/162769 https://www.ibm.com/support/pages/node/957207 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 displays sensitive information in HTTP requests which could be used in further attacks against the system. IBM X-Force ID: 160503. IBM Sterling File Gateway versiones 2.2.0.0 hasta 6.0.1.0, muestra información confidencial en peticiones HTTP que podría ser usada en futuros ataques contra el sistema. ID de IBM X-Force: 160503. • https://exchange.xforce.ibmcloud.com/vulnerabilities/160503 https://www.ibm.com/support/pages/node/957207 • CWE-319: Cleartext Transmission of Sensitive Information •

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 0

IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 158413. IBM Sterling File Gateway versiones 2.2.0.0 hasta 6.0.1.0, es vulnerable a la inyección SQL. Un atacante remoto podría enviar sentencias SQL especialmente diseñadas, lo que podría permitir al atacante visualizar, agregar, modificar o eliminar información en la base de datos del back-end. • https://exchange.xforce.ibmcloud.com/vulnerabilities/158413 https://www.ibm.com/support/pages/security-bulletin-sql-injection-vulnerability-affects-ibm-sterling-file-gateway-cve-2019-4147 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) uses weaker than expected cryptographic algorithms that could allow a local attacker to decrypt highly sensitive information. IBM X-Force ID: 132032. IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway desde la versión 2.2.0 hasta la 2.2.6) emplea algoritmos criptográficos más débiles de lo esperado que podrían permitir que un atacante local descifre información altamente sensible. IBM X-Force ID: 132032. • http://www.ibm.com/support/docview.wss?uid=ibm10716997 http://www.securityfocus.com/bid/104885 https://exchange.xforce.ibmcloud.com/vulnerabilities/132032 • CWE-327: Use of a Broken or Risky Cryptographic Algorithm •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote attacker to download certain files that could contain sensitive information. IBM X-Force ID: 138434. IBM Sterling File Gateway desde la versión 2.2.0 hasta la 2.2.6 podría permitir que un atacante remoto descargue ciertos archivos que podrían contener información sensible. IBM X-Force ID: 138434. • http://www.ibm.com/support/docview.wss?uid=ibm10717025 http://www.securityfocus.com/bid/104919 https://exchange.xforce.ibmcloud.com/vulnerabilities/138434 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •