CVE-2020-4647

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
16/11/2020
Last modified:
23/11/2020

Description

IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:sterling_file_gateway:*:*:*:*:*:*:*:* 2.2.0.0 (including) 2.2.6.5 (including)
cpe:2.3:a:ibm:sterling_file_gateway:*:*:*:*:*:*:*:* 6.0.0.0 (including) 6.0.3.2 (including)