Known vulnerabilities in IBM Sterling File Gateway - page 2
Vendor:
IBM Corporation
Software:
IBM Sterling File Gateway
Software CPE:
cpe:2.3:a:ibm_corporation:ibm_sterling_file_gateway:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
74
Public exploits:
5
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
6.2.0.6.1
6.2.2.1
6.2.1.2
6.2.0.6
6.2.2.0.1
6.2.1.1.2
6.2.0.5.2
6.2.2.0
6.2.1.1_1
6.2.0.5_1
6.1.2.8
6.2.1.1.1
6.2.0.5.1
6.2.0.4
6.1.2.7.2
6.2.1.1
6.1.2.7.1
6.2.1.0
6.2.0.5
6.1.2.7
6.1.2.0
6.1.1.2
6.1.0.5
6.0.3.7
6.2.0.3
6.2.0.2
6.1.2.6
6.2.0.1
6.1.2.5
6.2.0.0
6.1.2.4
6.1.0.8
6.0.3.9
6.0.3.3
5.2.6.5_3
6.0.3.2
2.2.0.0
6.1.1.0
6.1.0.0
6.0.0.0
Vulnerabilities (74)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU124131 - Missing Authentication for Critical Function CVE-2026-1264 |
CWE-306 | Medium | 6.1.2.8, 6.2.0.5.2, 6.2.1.1.2, 6.2.2.0.1 | 19.03.2026 |
SB2026031937 |
||
| #VU124130 - Command injection CVE-2025-14031 |
CWE-77 | High | 6.1.2.8, 6.2.0.5.2, 6.2.1.1.2, 6.2.2.0.1 | 19.03.2026 |
SB2026031936 |
||
| #VU123962 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2026-0835 |
CWE-79 | Low | 6.1.2.8, 6.2.0.5.2, 6.2.1.1.2, 6.2.2.0.1 | 12.03.2026 |
SB2026031243 |
||
| #VU123961 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2025-14504 |
CWE-79 | Low | 6.1.2.8, 6.2.0.5.2, 6.2.1.1.2, 6.2.2.0.1 | 12.03.2026 |
SB2026031242 |
||
| #VU123960 - Insertion of Sensitive Information Into Sent Data CVE-2025-14483 |
CWE-201 | Low | 6.1.2.8, 6.2.0.5.2, 6.2.1.1.2, 6.2.2.0.1 | 12.03.2026 |
SB2026031241 |
||
| #VU117443 - Improper input validation CVE-2025-5878 |
CWE-20 | Medium | 6.2.0.5.1, 6.2.1.1.1 | 22.10.2025 |
SB2025102210 SB2025112483 SB2026020448 and 1 more |
||
| #VU117439 - Improper input validation CVE-2025-48795 |
CWE-20 | Low | 6.1.2.7.2, 6.2.0.5.1, 6.2.1.1.1 | 22.10.2025 |
SB2025102238 SB2025102279 SB2025102286 and 9 more |
||
| #VU117413 - Unprotected Storage of Credentials CVE-2025-36002 |
CWE-256 | Low | 6.2.0.5.1, 6.2.1.1 | 21.10.2025 |
SB2025102148 SB2025102149 |
||
| #VU117197 - Improper input validation CVE-2025-59250 |
CWE-20 | High | 6.1.2.8, 6.2.0.5.2, 6.2.1.1.2, 6.2.2.0 | 15.10.2025 |
SB2025101554 SB2025121145 SB2025122942 and 6 more |
||
| #VU116142 - Uncontrolled Recursion CVE-2025-53864 |
CWE-674 | Medium | 6.2.0.6, 6.2.1.2, 6.2.2.0 | 26.09.2025 |
SB2025092630 SB2025092631 SB2025100301 and 27 more |
||
| #VU115571 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2025-36000 |
CWE-79 | Low | 6.1.2.8, 6.2.0.5_1, 6.2.1.1_1, 6.2.2.0 | 16.09.2025 |
SB20250916311 SB20250916316 SB2025092515 and 25 more |
||
| #VU114974 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2025-2694 |
CWE-79 | Low | 6.1.2.7.1, 6.2.0.4 | 08.09.2025 |
SB20250908106 |
||
| #VU114928 - Exposure of Sensitive System Information to an Unauthorized Control Sphere CVE-2025-2667 |
CWE-497 | Low | 6.1.2.7.2, 6.2.0.5, 6.2.1.1 | 08.09.2025 |
SB2025090864 |
||
| #VU113023 - Exposure of sensitive information to an unauthorized actor CVE-2025-22227 |
CWE-200 | Medium | 6.2.0.5.1, 6.2.1.1.1 | 17.07.2025 |
SB2025071765 SB2025072908 SB2025112532 and 6 more |
||
| #VU111165 - Improper Access Control CVE-2025-48734 |
CWE-284 | Medium | 6.1.2.7.2, 6.2.0.5.1, 6.2.1.1.1 | 16.06.2025 |
SB2025061643 SB2025061644 SB2025061645 and 141 more |
||
| #VU111162 - Resource exhaustion CVE-2025-48976 |
CWE-400 | Medium | 6.2.0.4, 6.2.0.5.1, 6.2.1.1.1 | 16.06.2025 |
SB2025061634 SB2025061635 SB2025061927 and 156 more |
||
| #VU100259 - Resource Management Errors CVE-2024-47535 |
CWE-399 | Low | 6.1.2.7.1, 6.2.0.5, 6.2.1.1 | 12.11.2024 |
SB2024111299 SB2024122313 SB2025012061 and 79 more |
||
| #VU83992 - Use of Insufficiently Random Values CVE-2020-36732 |
CWE-330 | Medium | 6.1.2.8, 6.2.0.5.2, 6.2.1.1.2, 6.2.2.0 | 08.12.2023 |
SB2023120804 SB2024030742 SB2025091116 and 26 more |
||
| #VU79797 - Improper input validation CVE-2023-32731 |
CWE-20 | Medium | 6.2.0.5.1, 6.2.1.1.1 | 21.08.2023 |
SB2023082198 SB2023082860 SB2023091213 and 28 more |
||
| #VU79796 - Improper input validation CVE-2023-32732 |
CWE-20 | Medium | 6.2.0.5.1, 6.2.1.1.1 | 21.08.2023 |
SB2023082198 SB20230821106 SB20230821107 and 16 more |
Showing elements 21 - 40 out of 74