IBM Sterling File Gateway Username Enumeration Vulnerability

Vulnerability

A vulnerability in IBM Sterling File Gateway versions 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 allows authenticated users to enumerate usernames. This issue arises from an observable discrepancy in request responses, which can be exploited to gather information about user accounts.

Impact

Exploitation of this vulnerability could lead to unauthorized username enumeration, allowing attackers to identify valid user accounts.

Remediation

Users can upgrade to IBM Sterling File Gateway versions 6.1.2.6 or 6.2.0.3. The IIM versions of these releases are available on Fix Central, while the container versions can be found in the IBM Entitled Registry.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
0.6
exploitability
5.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.