Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-78438
HistoryOct 09, 2021 - 12:00 a.m.

IBM Sterling File Gateway Cross-Site Scripting Vulnerability (CNVD-2021-78438)

2021-10-0900:00:00
China National Vulnerability Database
www.cnvd.org.cn
8

0.001 Low

EPSS

Percentile

29.8%

IBM Sterling File Gateway is an application for transferring files between internal and external partners, allowing you to more securely and reliably transfer files with trading partners.IBM Sterling File Gateway versions 2.2.0.0-5.2.6.5_4, 6.0.0.0-6.0.0.6, 6.0 .1.0-6.0.3.4, and 6.1.0.0-6.1.0.2 versions are vulnerable to cross-site scripting. An attacker could exploit the vulnerability to embed arbitrary JavaScript code in the Web UI, which could alter the intended functionality, which could lead to credential disclosure in a trusted session.

0.001 Low

EPSS

Percentile

29.8%

Related for CNVD-2021-78438