CVE Vulnerabilities

CVE-2024-47109

Insufficiently Protected Credentials

Published: Mar 10, 2025 | Modified: Jul 25, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure the installation path of the server which could aid in further attacks against the system.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

NameVendorStart VersionEnd Version
Sterling_file_gatewayIbm6.0.0.0 (including)6.1.2.7 (excluding)
Sterling_file_gatewayIbm6.2.0.0 (including)6.2.0.4 (excluding)

Potential Mitigations

References