Impact
The vulnerability allows a remote attacker to bypass proper authentication by injecting an unvalidated single sign‑on header. This results in the attacker obtaining a fully authenticated session, effectively granting them the same privileges as a legitimate user. The flaw stems from improper handling of authentication tokens and is classified as CWE-287.
Affected Systems
Affected versions of IBM Sterling File Gateway include 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 through 6.2.1.2, and 6.2.2.0 through 6.2.2.1. Patch releases are available as 6.2.0.6_2, 6.2.1.2_1, and 6.2.2.1_1, with container images for 6.2.1.2_1 and 6.2.2.1_1 hosted on the IBM Entitled Registry.
Risk and Exploitability
The CVSS score of 9.1 indicates a high impact and a high likelihood of exploitation if the vulnerability is not mitigated. Although the EPSS score is not publicly available, the absence of a KEV listing does not reduce the risk; the weakness can be exploited over the network by including a forged SSO header in an HTTP request, a feasible attack vector for remote actors. The vulnerability can lead to complete compromise of confidentiality, integrity, and availability for affected systems.
OpenCVE Enrichment