IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.
IBM strongly recommends addressing the vulnerability now.
Product
VersionAPARRemediation & FixIBM Sterling File Gateway6.2.0.0 - 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1IT49865Apply 6.2.0.6_2, 6.2.1.2_1 or 6.2.2.1_1
The IIM versions 6.2.1.2_1 and 6.2.2.1_1 are available on Fix Central http://www-933.ibm.com/support/fixcentral/swg/selectFixes .
The container versions of 6.2.1.2_1 and 6.2.2.1_1 are available in IBM Entitled Registry
- cp.icr.io/cp/ibm-sfg for IBM Sterling File Gateway
For 6.2.0.6_2, contact the support