IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 could disclose sensitive installation directory information to an authenticated user that could be used in further attacks against the system.
Solution:
The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/7239094 | vendor advisory |