CVE Vulnerabilities

CVE-2024-47109

Insufficiently Protected Credentials

Published: Mar 10, 2025 | Modified: Jul 25, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure the installation path of the server which could aid in further attacks against the system.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Sterling_file_gateway Ibm 6.0.0.0 (including) 6.1.2.7 (excluding)
Sterling_file_gateway Ibm 6.2.0.0 (including) 6.2.0.4 (excluding)

Potential Mitigations

References