VulnerabilityModified
CVE-2017-1497
IBM Sterling File Gateway 2.2 could allow an unauthorized user to view files they should not have access to providing they know the directory location of the file.
LOW 3.7EPSS 1.04%
Does this matter?
Lower severity and a low EPSS score (1.04%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Sterling File Gateway 2.2 could allow an unauthorized user to view files they should not have access to providing they know the directory location of the file. IBM X-Force ID: 128695.
- CVSS 3.0
- 3.7 LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.04% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/sterling file gateway
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=swg22010738Issue Tracking, Vendor Advisory
- http://www.securityfocus.com/bid/102187Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/128695Issue Tracking, VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22010738Issue Tracking, Vendor Advisory
- http://www.securityfocus.com/bid/102187Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/128695Issue Tracking, VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.