Page 4 of 23 results (0.008 seconds)

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162769. IBM Sterling File Gateway versiones 2.2.0.0 hasta 6.0.1.0, podría permitir a un atacante remoto saltar directorios en el sistema. Un atacante podría enviar una petición URL especialmente diseñada que contenga secuencias de "dot dot" (/../) para visualizar archivos arbitrarios en el sistema. • https://exchange.xforce.ibmcloud.com/vulnerabilities/162769 https://www.ibm.com/support/pages/node/957207 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 displays sensitive information in HTTP requests which could be used in further attacks against the system. IBM X-Force ID: 160503. IBM Sterling File Gateway versiones 2.2.0.0 hasta 6.0.1.0, muestra información confidencial en peticiones HTTP que podría ser usada en futuros ataques contra el sistema. ID de IBM X-Force: 160503. • https://exchange.xforce.ibmcloud.com/vulnerabilities/160503 https://www.ibm.com/support/pages/node/957207 • CWE-319: Cleartext Transmission of Sensitive Information •

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 0

IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 158413. IBM Sterling File Gateway versiones 2.2.0.0 hasta 6.0.1.0, es vulnerable a la inyección SQL. Un atacante remoto podría enviar sentencias SQL especialmente diseñadas, lo que podría permitir al atacante visualizar, agregar, modificar o eliminar información en la base de datos del back-end. • https://exchange.xforce.ibmcloud.com/vulnerabilities/158413 https://www.ibm.com/support/pages/security-bulletin-sql-injection-vulnerability-affects-ibm-sterling-file-gateway-cve-2019-4147 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) caches usernames and passwords in browsers that could be used by a local attacker to obtain sensitive information. IBM X-Force ID: 130812. IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway desde la versión 2.2.0 hasta la 2.2.6) cachea los nombres de usuario y las contraseñas en navegadores que podrían ser empleados por un atacante local para obtener información sensible. IBM X-Force ID: 130812. • http://www.ibm.com/support/docview.wss?uid=ibm10716997 http://www.securityfocus.com/bid/104885 https://exchange.xforce.ibmcloud.com/vulnerabilities/130812 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote attacker to download certain files that could contain sensitive information. IBM X-Force ID: 138434. IBM Sterling File Gateway desde la versión 2.2.0 hasta la 2.2.6 podría permitir que un atacante remoto descargue ciertos archivos que podrían contener información sensible. IBM X-Force ID: 138434. • http://www.ibm.com/support/docview.wss?uid=ibm10717025 http://www.securityfocus.com/bid/104919 https://exchange.xforce.ibmcloud.com/vulnerabilities/138434 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •